Known Vulnerabilities for products from Idreamsoft
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Idreamsoft".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2025-15394 json | A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of t... | Not Provided | 2025-12-31 | 2026-04-29 |
| CVE-2023-40953 json | icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). | 8.8 - HIGH | 2023-09-08 | 2023-09-12 |
| CVE-2023-39806 json | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. | Not Provided | 2023-08-10 | 2026-07-09 |
| CVE-2023-39805 json | iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. | Not Provided | 2023-08-10 | 2026-07-09 |
| CVE-2022-41496 json | iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. | 9.8 - CRITICAL | 2022-10-13 | 2022-10-14 |
| CVE-2021-44978 json | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execu... | 9.8 - CRITICAL | 2022-02-04 | 2022-02-08 |
| CVE-2021-44977 json | In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. | 7.5 - HIGH | 2022-02-04 | 2022-02-08 |
| CVE-2020-26641 json | A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitr... | 8.8 - HIGH | 2021-05-28 | 2021-06-03 |
| CVE-2020-24739 json | A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN a... | 6.5 - MEDIUM | 2020-09-10 | 2020-09-16 |
| CVE-2020-21141 json | iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. | 8.8 - HIGH | 2021-11-12 | 2021-11-16 |
| CVE-2020-19527 json | iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.p... | 9.8 - CRITICAL | 2020-12-10 | 2020-12-11 |
| CVE-2020-19142 json | iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php. | 9.8 - CRITICAL | 2020-12-10 | 2020-12-11 |
| CVE-2020-18070 json | Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to... | 9.1 - CRITICAL | 2021-04-30 | 2021-05-03 |
| CVE-2019-17583 json | idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comme... | 7.5 - HIGH | 2019-10-14 | 2020-08-24 |
| CVE-2019-17552 json | An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the ... | 9.8 - CRITICAL | 2019-10-14 | 2019-10-16 |
| CVE-2019-16677 json | An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. | 6.5 - MEDIUM | 2019-09-21 | 2019-09-23 |
| CVE-2019-11427 json | An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parame... | 6.1 - MEDIUM | 2019-04-22 | 2019-04-22 |
| CVE-2019-11426 json | An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=conf... | 6.1 - MEDIUM | 2019-04-22 | 2019-04-22 |
| CVE-2019-8902 json | An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api... | 5.7 - MEDIUM | 2019-02-18 | 2019-02-19 |
| CVE-2019-7237 json | An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=brows... | 7.5 - HIGH | 2019-01-30 | 2019-01-31 |
Known software with vulnerabilities from Idreamsoft
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Idreamsoft | Icms | 6.0.0 |