VYPR

Alchemy CMS

by Alchemy CMS

Source repositories

CVEs (2)

  • CVE-2018-18307MedOct 16, 2018
    risk 0.40cvss 6.1epss 0.01

    A Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's position is that this is not a valid report: "The researcher used an authorized cookie to perform the request to a password-protected route.…

  • CVE-2026-23885MedJan 19, 2026
    risk 0.35cvss 6.4epss 0.00

    Alchemy is an open source content management system engine written in Ruby on Rails. Prior to versions 7.4.12 and 8.0.3, the application uses the Ruby `eval()` function to dynamically execute a string provided by the `resource_handler.engine_name` attribute in…