Vulnerabilities
11 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-1776 | Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows a Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary files from the web server’s filesystem. The issue occurs in the download_private_file functionality when the application is configured to use the CamaleonCmsAwsUploader backend. Unlike the local uploader implementation, the AWS uploader does not validate file paths with valid_folder_path?, allowing directory traversal sequences to be supplied via the file parameter. As a result, any authenticated user, including low-privileged registered users, can access sensitive files such as /etc/passwd. This issue represents a bypass of the incomplete fix for CVE-2024-46987 and affects deployments using the AWS S3 storage backend. NVD description · AI analysis pending | 6.0 | <1% |
| — | ||
| CVE-2023-53936 | Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post title Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title, potentially stealing session cookies and executing arbitrary JavaScript. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2024-48652 | Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field. Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field. NVD description · AI analysis pending | 4.8 | 1% | PoC |
| — | |
| CVE-2024-46986 +1 in the same advisory: …46987 | Authenticated arbitrary file write in Camaleon CMS enables delayed RCE An authenticated arbitrary file write vulnerability exists in Camaleon CMS (versions before 2.8.2): the upload method of the MediaController does not properly constrain where uploaded files are written, so a user with low-privilege access can write files to any location on the web server, limited only by filesystem permissions. An attacker can abuse this by planting a Ruby file in the Rails config/initializers/ directory of the application, achieving delayed remote code execution when the application next loads, with critical impact (CVSS 9.9, high confidentiality/integrity/availability and scope change). Any deployment of Tuzitio's Camaleon CMS running a version prior to 2.8.2 is affected. No confirmed in-the-wild exploitation has been reported and the flaw is not in CISA KEV, but a public advisory with a proof-of-concept reference exists and EPSS assigns a 41% probability of exploitation within 30 days (99th percentile), so defenders should treat patching as urgent. Do: Upgrade to Camaleon CMS 2.8.2 or later, since there are no known workarounds. Restrict MediaController/upload access to trusted accounts and inspect the Rails config/initializers/ directory (and other writable paths) for unexpected or recently modified Ruby files that could indicate prior exploitation. Given the elevated EPSS score (41%, 99th percentile), prioritize patching immediately. | 9.9 group max | 41% | PoC |
| nichelikely hundreds to low thousands of deployments (niche open-source Rails CMS; no public install or scan counts available) | |
| CVE-2023-30145 | Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter. NVD description · AI analysis pending | 9.8 | 46% | PoC ×4 |
| — | |
| CVE-2021-25970 | Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was already logged in, will still have access to the application even after the password was changed. NVD description · AI analysis pending | 8.8 group max | 1% |
| — | ||
| CVE-2018-18260 | In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version." NVD description · AI analysis pending | 6.1 | 1% |
| — |