Known Vulnerabilities for Icms by Idreamsoft
Listed below are 10 of the newest known vulnerabilities associated with "Icms" by "Idreamsoft".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-4320 json | Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protect... | Not Provided | 2026-05-18 | 2026-05-18 |
| CVE-2025-15394 json | Not Provided | 2025-12-31 | 2026-04-29 | |
| CVE-2023-40953 json | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | 8.8 - HIGH | 2023-09-08 | 2023-09-12 |
| CVE-2023-39806 json | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. | 8.8 - HIGH | 2023-08-10 | 2026-07-09 |
| CVE-2023-39805 json | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. | 8.8 - HIGH | 2023-08-10 | 2026-07-09 |
| CVE-2022-41496 json | iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. | 9.8 - CRITICAL | 2022-10-13 | 2022-10-14 |
| CVE-2021-44978 json | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execu... | 9.8 - CRITICAL | 2022-02-04 | 2022-02-08 |
| CVE-2021-44977 json | In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. | 7.5 - HIGH | 2022-02-04 | 2022-02-08 |
| CVE-2020-26641 json | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitr... | 8.8 - HIGH | 2021-05-28 | 2021-06-03 |
| CVE-2020-24739 json | A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN a... | 6.5 - MEDIUM | 2020-09-10 | 2020-09-16 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Idreamsoft | Icms | 7.0.9 | |||
| Application | Idreamsoft | Icms | 7.0.8 | |||
| Application | Idreamsoft | Icms | 7.0.7 | |||
| Application | Idreamsoft | Icms | 7.0.6 | |||
| Application | Idreamsoft | Icms | 7.0.5 | |||
| Application | Idreamsoft | Icms | 7.0.4 | |||
| Application | Idreamsoft | Icms | 7.0.3 | |||
| Application | Idreamsoft | Icms | 7.0.2 | |||
| Application | Idreamsoft | Icms | 7.0.15 | |||
| Application | Idreamsoft | Icms | 7.0.14 | |||
| Application | Idreamsoft | Icms | 7.0.13 | |||
| Application | Idreamsoft | Icms | 7.0.12 | |||
| Application | Idreamsoft | Icms | 7.0.11 | |||
| Application | Idreamsoft | Icms | 7.0.10 | |||
| Application | Idreamsoft | Icms | 7.0.1 | |||
| Application | Idreamsoft | Icms | 7.0.0 | |||
| Application | Idreamsoft | Icms | 6.0.9 | |||
| Application | Idreamsoft | Icms | 6.0.8 | |||
| Application | Idreamsoft | Icms | 6.0.7 | |||
| Application | Idreamsoft | Icms | 6.0.6 |