Known Vulnerabilities for products from Idreamsoft

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Idreamsoft".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2025-15394 json A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of t... Not Provided 2025-12-31 2026-04-29
CVE-2023-40953 json icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF). 8.8 - HIGH 2023-09-08 2023-09-12
CVE-2023-39806 json iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function. Not Provided 2023-08-10 2026-07-09
CVE-2023-39805 json iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php. Not Provided 2023-08-10 2026-07-09
CVE-2022-41496 json iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php. 9.8 - CRITICAL 2022-10-13 2022-10-14
CVE-2021-44978 json iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execu... 9.8 - CRITICAL 2022-02-04 2022-02-08
CVE-2021-44977 json In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files. 7.5 - HIGH 2022-02-04 2022-02-08
CVE-2020-26641 json A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitr... 8.8 - HIGH 2021-05-28 2021-06-03
CVE-2020-24739 json A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN a... 6.5 - MEDIUM 2020-09-10 2020-09-16
CVE-2020-21141 json iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add. 8.8 - HIGH 2021-11-12 2021-11-16
CVE-2020-19527 json iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.p... 9.8 - CRITICAL 2020-12-10 2020-12-11
CVE-2020-19142 json iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php. 9.8 - CRITICAL 2020-12-10 2020-12-11
CVE-2020-18070 json Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to... 9.1 - CRITICAL 2021-04-30 2021-05-03
CVE-2019-17583 json idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comme... 7.5 - HIGH 2019-10-14 2020-08-24
CVE-2019-17552 json An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the ... 9.8 - CRITICAL 2019-10-14 2019-10-16
CVE-2019-16677 json An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF. 6.5 - MEDIUM 2019-09-21 2019-09-23
CVE-2019-11427 json An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parame... 6.1 - MEDIUM 2019-04-22 2019-04-22
CVE-2019-11426 json An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=conf... 6.1 - MEDIUM 2019-04-22 2019-04-22
CVE-2019-8902 json An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api... 5.7 - MEDIUM 2019-02-18 2019-02-19
CVE-2019-7237 json An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=brows... 7.5 - HIGH 2019-01-30 2019-01-31

Known software with vulnerabilities from Idreamsoft

Type Vendor Product Version
ApplicationIdreamsoftIcms6.0.0

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report