VYPR

CamaleonCMS

by CamaleonCMS

Source repositories

CVEs (7)

  • CVE-2026-73332HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers to inject arbitrary HTML by submitting unsanitized content to the before_html field through the contact form edit endpoint, which…

  • CVE-2026-73329HigAug 12, 2026
    risk 0.57cvss 8.7epss 0.00

    CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an administrator's browser by injecting unsanitized HTML payloads into the post title parameter during draft creation. Attackers can…

  • CVE-2026-56721HigAug 11, 2026
    risk 0.50cvss 8.8epss 0.01

    CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authenticated low-privileged attackers to overwrite any user's credentials by exploiting a parameter confusion flaw between the…

  • CVE-2026-73326HigAug 12, 2026
    risk 0.49cvss 7.6epss 0.00

    CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by reaching four unprotected plugin-administration endpoints without administrator-level authorization. Attackers can manipulate…

  • CVE-2026-73331HigAug 12, 2026
    risk 0.39cvss 7.1epss 0.00

    CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges to submit a crafted slug value containing SQL syntax that the database backend evaluates as part of an inadequately parameterized…

  • CVE-2026-73330MedAug 12, 2026
    risk 0.36cvss 6.6epss 0.01

    CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects…

  • CVE-2026-56720MedAug 11, 2026
    risk 0.21cvss 4.3epss 0.00

    CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that allows any authenticated user to access any other user's profile data by supplying an arbitrary user ID parameter. Attackers can send a GET request to the…