Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    4
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47964

    Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanager

    Last Modified: May 18, 2026
    Published: May 15, 2026

    CVE-2021-47834

    Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)

    Last Modified: Apr 15, 2026
    Published: Jan 16, 2026

    CVE-2025-67443

    Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.

    Last Modified: Jan 02, 2026
    Published: Dec 22, 2025

    CVE-2023-31505

    An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

    Last Modified: Jun 20, 2025
    Published: Jan 31, 2024

    CVE-2022-45544

    Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to upload new executable PHP code, such as a theme that was obtained from a trusted source or was developed for their own website. Only an admin can upload such code, not someone else in an "attacker" role.

    Last Modified: Nov 21, 2024
    Published: Feb 07, 2023
    Items Per Page