CuppacmsCVEs & Vulnerabilities

25 CVEs affecting Cuppacms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

cuppacms 25
CVE-2022-25485KEVHIGHin the wild

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

11 Apr 2026
7.8
CVSS
CVE-2022-25486KEVHIGHin the wild

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

11 Apr 2026
7.8
CVSS
CVE-2022-34121KEVHIGHin the wild

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

11 Apr 2026
7.5
CVSS
CVE-2022-38296KEVCRITICALin the wild

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

11 Apr 2026
9.8
CVSS
CVE-2023-47990CRITICAL

SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

20 Dec 2023
9.8
CVSS
CVE-2023-39681CRITICAL

Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.

5 Sep 2023
9.8
CVSS
CVE-2021-29368HIGH

Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.

20 Jan 2023
8.8
CVSS
CVE-2022-37191MEDIUM

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

14 Sep 2022
6.5
CVSS
CVE-2022-37190HIGH

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

14 Sep 2022
8.8
CVSS
CVE-2022-38295MEDIUM

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

13 Sep 2022
6.1
CVSS
CVE-2022-27985CRITICAL

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

26 Apr 2022
9.8
CVSS
CVE-2022-27984CRITICAL

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

26 Apr 2022
9.8
CVSS
CVE-2022-25498CRITICAL

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

15 Mar 2022
9.8
CVSS
CVE-2022-25497MEDIUM

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

15 Mar 2022
5.3
CVSS
CVE-2022-25495CRITICAL

The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

15 Mar 2022
9.8
CVSS
CVE-2022-25401HIGH

The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.

24 Feb 2022
7.5
CVSS
CVE-2022-24647HIGH

Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

11 Feb 2022
8.1
CVSS
CVE-2022-24266HIGH

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

1 Feb 2022
7.5
CVSS
CVE-2022-24265HIGH

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

1 Feb 2022
7.5
CVSS
CVE-2022-24264HIGH

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

1 Feb 2022
7.5
CVSS
CVE-2021-3376HIGH

An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using the user_group_id_field parameter.

14 Dec 2021
8.8
CVSS
CVE-2020-26048HIGH

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

5 Oct 2020
8.8
CVSS
CVE-2018-19918MEDIUM

CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

31 Dec 2018
5.4
CVSS
CVE-2018-19559CRITICAL

CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

26 Nov 2018
9.8
CVSS
CVE-2018-17300MEDIUM

Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.

21 Sep 2018
4.8
CVSS
← PrevPage 1 / 1Next →