VYPR
Vendor

Camaleon CMS

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2023-30145CriMay 26, 2023
    risk 0.63cvss 9.8epss 0.46

    Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

  • CVE-2026-86100MedSep 5, 2026
    risk 0.35cvss 6.4epss 0.00

    Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redirect to internal network addresses, allowing server-side…

  • CVE-2026-10715MedJun 12, 2026
    risk 0.33cvss epss 0.00

    Camaleon CMS 2.9.2 contains an improper authorization vulnerability in the administrator draft autosave endpoint. A low-privileged authenticated user can send an arbitrary post_id to POST /admin/post_type/<POST_TYPE_ID>/drafts and overwrite the draft associated with another…

  • CVE-2024-48652MedOct 22, 2024
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.

  • CVE-2026-67616MedAug 3, 2026
    risk 0.21cvss 4.3epss 0.00

    Camaleon CMS through 2.9.2, fixed in commit 88ab703, contains a missing authorization vulnerability on the drafts endpoint that allows any authenticated low-privileged user to create draft posts by bypassing role and permission checks. Attackers can send requests to the drafts…

  • CVE-2026-66748HigJul 28, 2026
    risk 0.00cvss 8.8epss 0.01

    Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage permission to execute arbitrary Ruby code by supplying a malicious expression through the select_eval custom field type. Attackers…