Vulnerabilities
30 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-30661 | iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2025-15394 | A vulnerability was detected in iCMS up to 8.0.0. A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 2.0 | <1% | PoC |
| — | |
| CVE-2023-40953 | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2023-39806 +1 in the same advisory: …39805 | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. NVD description · AI analysis pending | 9.8 | <1% |
| — | ||
| CVE-2022-41496 | iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2021-44978 +1 in the same advisory: …44977 | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution. iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution. NVD description · AI analysis pending | 9.8 group max | 2% |
| — | ||
| CVE-2020-21141 | iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-26641 | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts. A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2020-18070 | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the compo Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php". NVD description · AI analysis pending | 9.1 | 2% | PoC |
| — | |
| CVE-2020-19527 +1 in the same advisory: …19142 | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php. NVD description · AI analysis pending | 9.8 | 2% | PoC |
| — | |
| CVE-2020-24739 | A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2019-17552 +1 in the same advisory: …17583 | An issue was discovered in idreamsoft iCMS v7.0.14. An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload. NVD description · AI analysis pending | 9.8 group max | 1% | PoC |
| — | |
| CVE-2019-16677 | An issue was discovered in idreamsoft iCMS V7.0. An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2019-11427 +1 in the same advisory: …11426 | An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter. An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2019-8902 | An issue was discovered in idreamsoft iCMS through 7.0.14. An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI. NVD description · AI analysis pending | 5.7 | <1% | PoC |
| — | |
| CVE-2019-7234 | An issue was discovered in idreamsoft iCMS 7.0.13. An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file can then be downloaded via an admincp.php?app=apps&do=pack request. NVD description · AI analysis pending | 9.1 group max | 2% | PoC |
| — | |
| CVE-2019-7160 | idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php. NVD description · AI analysis pending | 9.8 | 3% | PoC |
| — | |
| CVE-2018-16366 | An issue was discovered in idreamsoft iCMS V7.0.10. An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2018-16320 | idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file. idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file. NVD description · AI analysis pending | 7.2 | 2% |
| — | ||
| CVE-2018-13865 | An issue was discovered in idreamsoft iCMS 7.0.9. An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — |