VYPR

CMS

by Schlix

CVEs (6)

  • CVE-2021-47964HigMay 15, 2026
    risk 0.57cvss 8.8epss 0.01

    Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the…

  • CVE-2022-45544HigFeb 7, 2023
    risk 0.57cvss 8.8epss 0.01

    Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to upload new executable PHP…

  • CVE-2023-31505HigJan 31, 2024
    risk 0.47cvss 7.2epss 0.01

    An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

  • CVE-2019-11021HigOct 24, 2019
    risk 0.47cvss 7.2epss 0.02

    admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin permission. We think it's…

  • CVE-2021-47834MedJan 16, 2026
    risk 0.42cvss 6.4epss 0.00

    Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other…

  • CVE-2025-67443MedDec 22, 2025
    risk 0.40cvss 6.1epss 0.00

    Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.