CouchCMS
CouchCMS · 4 CVEs
CVE-2021-47955
MEDIUM
CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload
May 16, 2026
CVE-2021-47958
MEDIUM
CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload
May 15, 2026
CVE-2026-29002
HIGH
CouchCMS Privilege Escalation via f_k_levels_list Parameter
Apr 10, 2026
CVE-2025-67004
MEDIUM
** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via…
Jan 9, 2026
CVE-2025-15005
MEDIUM
CouchCMS reCAPTCHA config.example.php hard-coded key
Dec 22, 2025
CVE-2023-41609
MEDIUM
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim u…
Sep 11, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-47955 | CouchCMS 2.2.1 Cross-Site Scripting via SVG File Upload | MEDIUM | 0.17% | May 16, 2026 |
| CVE-2021-47958 | CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload | MEDIUM | 0.24% | May 15, 2026 |
| CVE-2026-29002 | CouchCMS Privilege Escalation via f_k_levels_list Parameter | HIGH | 0.66% | Apr 10, 2026 |
| CVE-2025-67004 | ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directories back after back.… | MEDIUM | 6.12% | Jan 9, 2026 |
| CVE-2025-15005 | CouchCMS reCAPTCHA config.example.php hard-coded key | MEDIUM | 0.46% | Dec 22, 2025 |
| CVE-2023-41609 | An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary web site via a craft… | MEDIUM | 0.41% | Sep 11, 2023 |
Showing 1 to 4 of 4 CVEs