Known Vulnerabilities for Evolution Cms by Evo
Listed below are 3 of the newest known vulnerabilities associated with "Evolution Cms" by "Evo".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-91997 json | evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates... | Not Provided | 2026-09-15 | 2026-09-15 |
| CVE-2026-88859 json | A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email con... | Not Provided | 2026-09-10 | 2026-09-10 |
| CVE-2026-18992 json | A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the f... | Not Provided | 2026-08-06 | 2026-08-06 |
| CVE-2025-51989 json | HTML injection vulnerability in the registration interface in Evolution Consulting Kft. HRmaster module v235 allows an attack... | Not Provided | 2025-08-21 | 2026-07-05 |
| CVE-2023-43341 json | Cross-site scripting (XSS) vulnerability in evolution evo v.3.2.3 allows a local attacker to execute arbitrary code via a cra... | 6.1 - MEDIUM | 2023-10-19 | 2023-10-30 |
| CVE-2023-43340 json | Cross-site scripting (XSS) vulnerability in evolution v.3.2.3 allows a local attacker to execute arbitrary code via a crafted... | 5.2 - MEDIUM | 2023-10-19 | 2023-10-27 |
| CVE-2020-23238 json | Cross Site Scripting (XSS) vulnerability in Evolution CMS 2.0.2 via the Document Manager feature. | 5.4 - MEDIUM | 2021-07-26 | 2021-07-30 |