Vendor
Chameleon CMS
Products
1
CVEs
4
Across products
4
Status
Private
Products
1- 4 CVEs
Recent CVEs
4| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-6252 | Hig | 0.49 | 7.5 | 0.01 | Nov 22, 2023 | Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read files located on the server and gain access to sensitive information such as configuration files. | ||
| CVE-2023-53936 | Med | 0.31 | 4.8 | 0.00 | Dec 18, 2025 | Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title,… | ||
| CVE-2007-3050 | 0.00 | — | 0.02 | Jun 6, 2007 | Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | |||
| CVE-1999-0261 | 0.00 | — | 0.01 | Mar 1, 1999 | Netmanager Chameleon SMTPd has several buffer overflows that cause a crash. |
- risk 0.49cvss 7.5epss 0.01
Path traversal vulnerability in Chalemelon Power framework, affecting the getImage parameter. This vulnerability could allow a remote user to read files located on the server and gain access to sensitive information such as configuration files.
- risk 0.31cvss 4.8epss 0.00
Cameleon CMS 2.7.4 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts into post titles. Attackers can create posts with embedded SVG scripts that execute when other users mouse over the post title,…
- CVE-2007-3050Jun 6, 2007risk 0.00cvss —epss 0.02
Session fixation vulnerability in chameleon cms 3.0 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.
- CVE-1999-0261Mar 1, 1999risk 0.00cvss —epss 0.01
Netmanager Chameleon SMTPd has several buffer overflows that cause a crash.