VYPR

Camaleon CMS

by Camaleon CMS

CVEs (5)

  • CVE-2026-56721HigAug 11, 2026
    risk 0.50cvss 8.8epss

    CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the…

  • CVE-2026-10715MedJun 12, 2026
    risk 0.33cvss epss 0.00

    Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another…

  • CVE-2026-56720MedAug 11, 2026
    risk 0.21cvss 4.3epss

    CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the…

  • CVE-2026-67616MedAug 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts…

  • CVE-2026-66748HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.01

    Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers…