VYPR
Vendor

Impresscms

Products
2
CVEs
24
Across products
24
Status
Private

Products

2

Recent CVEs

24
View all 24 CVEs →
  • CVE-2022-50912CriJan 13, 2026
    risk 0.64cvss 9.8epss 0.01

    ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary…

  • CVE-2021-26599CriMar 28, 2022
    risk 0.61cvss 9.8epss 0.21

    ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

  • CVE-2021-47938HigMay 10, 2026
    risk 0.57cvss 8.8epss 0.01

    ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers can authenticate, submit a POST request…

  • CVE-2021-26600CriMar 28, 2022
    risk 0.57cvss 9.8epss 0.06

    ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

  • CVE-2022-24977CriFeb 14, 2022
    risk 0.57cvss 9.8epss 0.06

    ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP…

  • CVE-2022-26986HigApr 5, 2022
    risk 0.50cvss 7.2epss 0.04

    SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a…

  • CVE-2026-73679HigAug 14, 2026
    risk 0.47cvss 7.2epss

    ImpressCMS contains an authenticated remote code execution vulnerability in the custom tag module that allows authenticated administrators to execute arbitrary PHP code by storing a malicious payload in a custom tag with PHP type enabled. The application decodes HTML-encoded…

  • CVE-2019-25703HigApr 12, 2026
    risk 0.46cvss 7.1epss 0.00

    ImpressCMS 1.3.11 contains a time-based blind SQL injection vulnerability that allows authenticated attackers to manipulate database queries by injecting SQL code through the 'bid' parameter. Attackers can send POST requests to the admin.php endpoint with malicious 'bid' values…

  • CVE-2018-13983MedMay 6, 2019
    risk 0.40cvss 6.1epss 0.02

    ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.

  • CVE-2025-29930MedMar 18, 2025
    risk 0.38cvss epss 0.00

    imFAQ is an advanced questions and answers management system for ImpressCMS. Prior to 1.0.1, if the $_GET['seoOp'] parameter is manipulated to include malicious input (e.g., seoOp=php://filter/read=convert.base64-encode/resource=/var/www/html/config.php), the application could…

  • CVE-2021-28088MedMar 11, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.

  • CVE-2023-37785MedJul 13, 2023
    risk 0.31cvss 4.8epss 0.00

    A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.

  • CVE-2020-17551MedOct 7, 2020
    risk 0.31cvss 4.8epss 0.01

    ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.

  • CVE-2014-1836Jul 1, 2015
    risk 0.03cvss epss 0.04

    Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

  • CVE-2021-26598MedMar 28, 2022
    risk 0.01cvss 5.3epss 0.11

    ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

  • CVE-2021-26601HigMar 28, 2022
    risk 0.00cvss 8.1epss 0.03

    ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

  • CVE-2014-4036Jun 11, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.

  • CVE-2012-0987Oct 6, 2012
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the icmsConfigPlugins[sanitizer_plugins][] parameter.

  • CVE-2012-0986Oct 6, 2012
    risk 0.00cvss epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3)…

  • CVE-2010-4616Dec 29, 2010
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before 1.2.4, allows remote attackers to inject arbitrary web script or HTML via the quicksearch_ContentContent parameter.