Exponentcms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 61
    Known Exploited: 0
    33
    Critical Level Threats
    14
    High Level Threats
    14
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47931

    Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication

    Last Modified: May 26, 2026
    Published: May 10, 2026

    CVE-2021-32441

    SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.

    Last Modified: Mar 19, 2025
    Published: Feb 17, 2023

    CVE-2022-23049

    Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2022

    CVE-2022-23048

    Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2022

    CVE-2022-23047

    Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2022
    Items Per Page
    Exponentcms Vulnerabilities & Security CVEs | CVE-DB