VendorsiDreamSofticmsall versions
Vulnerabilities

iDreamSoft iCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

30CVEs
CVE-2020-19527
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
Published 2020-12-10 · Modified
10.0EPSS 0.016
CVE-2020-19142
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
Published 2020-12-10 · Modified
10.0EPSS 0.016
CVE-2019-7160
idreamsoft iCMS 7.0.13 allows admincp.php?app=files ../ Directory Traversal via the udir parameter to files.admincp.php, resulting in execution of arbitrary PHP code from a ZIP file via the admincp.php?app=apps zipfile parameter to apps.admincp.php.
Published 2019-01-29 · Modified
9.8EPSS 0.034
CVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
Published 2022-02-04 · Modified
9.8EPSS 0.022
CVE-2019-17552
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
Published 2019-10-14 · Modified
9.8EPSS 0.011
CVE-2022-41496
iCMS v7.0.16 was discovered to contain a Server-Side Request Forgery (SSRF) via the url parameter at admincp.php.
Published 2022-10-13 · Modified
9.8EPSS 0.010
CVE-2023-39806
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the bakupdata function.
Published 2023-08-10 · Modified
9.8EPSS 0.006
CVE-2023-39805
iCMS v7.0.16 was discovered to contain a SQL injection vulnerability via the where parameter at admincp.php.
Published 2023-08-10 · Modified
9.8EPSS 0.006
CVE-2019-7234
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to begin the process of creating a ZIP archive file with the complete contents of any directory because of an apps.admincp.php error. This ZIP archive file can then be downloaded via an admincp.php?app=apps&do=pack request.
Published 2019-01-30 · Modified
9.1EPSS 0.022
CVE-2020-18070
Path Traversal in iCMS v7.0.13 allows remote attackers to delete folders by injecting commands into a crafted HTTP request to the "do_del()" method of the component "database.admincp.php".
Published 2021-04-29 · Modified
9.1EPSS 0.022
CVE-2018-16366
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=user&do=save allows CSRF.
Published 2018-09-02 · Modified
8.8EPSS 0.006
CVE-2018-16365
An issue was discovered in idreamsoft iCMS V7.0.10. admincp.php?app=group&do=save allows CSRF.
Published 2018-09-02 · Modified
8.8EPSS 0.006
CVE-2018-16332
An issue was discovered in iCMS 7.0.9. There is an admincp.php?app=article&do=update CSRF vulnerability.
Published 2018-09-02 · Modified
8.8EPSS 0.006
CVE-2020-21141
iCMS v7.0.15 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admincp.php?app=members&do=add.
Published 2021-11-12 · Modified
8.8EPSS 0.006
CVE-2020-26641
A Cross Site Request Forgery (CSRF) vulnerability was discovered in iCMS 7.0.16 which can allow an attacker to execute arbitrary web scripts.
Published 2021-05-28 · Modified
8.8EPSS 0.005
CVE-2023-40953
icms 7.0.16 is vulnerable to Cross Site Request Forgery (CSRF).
Published 2023-09-08 · Modified
8.8EPSS 0.003
CVE-2019-7235
An issue was discovered in idreamsoft iCMS 7.0.13. admincp.php?app=apps&do=save allows directory traversal via _app=/../ to designate an arbitrary directory because of an apps.admincp.php error. This directory can then be deleted via an admincp.php?app=apps&do=uninstall request.
Published 2019-01-30 · Modified
7.5EPSS 0.025
CVE-2019-7236
An issue was discovered in idreamsoft iCMS 7.0.13. editor/editor.admincp.php allows admincp.php?app=editor&do=fileManager dir=../ Directory Traversal.
Published 2019-01-30 · Modified
7.5EPSS 0.022
CVE-2019-7237
An issue was discovered in idreamsoft iCMS 7.0.13 on Windows. editor/editor.admincp.php allows admincp.php?app=files&do=browse ..\ Directory Traversal.
Published 2019-01-30 · Modified
7.5EPSS 0.022
CVE-2021-44977
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
Published 2022-02-04 · Modified
7.5EPSS 0.016
CVE-2019-17583
idreamsoft iCMS 7.0.15 allows remote attackers to cause a denial of service (resource consumption) via a query for many comments, as demonstrated by the admincp.php?app=comment&perpage= substring followed by a large positive integer.
Published 2019-10-14 · Modified
7.5EPSS 0.013
CVE-2018-16320
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
Published 2018-09-01 · Modified
7.2EPSS 0.024
CVE-2025-15394
iCMS POST Parameter ConfigAdmincp.php save code injection
Published 2025-12-31 · Analyzed
7.2EPSS 0.005
CVE-2019-16677
An issue was discovered in idreamsoft iCMS V7.0. admincp.php?app=members&do=del allows CSRF.
Published 2019-09-21 · Modified
6.5EPSS 0.005
CVE-2020-24739
A CSRF vulnerability was found in iCMS v7.0.0 in the background deletion administrator account. When missing the CSRF_TOKEN and can still request normally, all administrators except the initial administrator will be deleted.
Published 2020-09-10 · Modified
6.5EPSS 0.004
CVE-2018-13865
An issue was discovered in idreamsoft iCMS 7.0.9. XSS exists via the callback parameter in a public/api.php uploadpic request, bypassing the iWAF protection mechanism.
Published 2018-07-10 · Modified
6.1EPSS 0.010
CVE-2019-11427
An XSS issue was discovered in app/search/search.app.php in idreamsoft iCMS 7.0.14 via the public/api.php?app=search q parameter.
Published 2019-04-21 · Modified
6.1EPSS 0.008
CVE-2019-11426
An XSS issue was discovered in app/admincp/template/admincp.header.php in idreamsoft iCMS 7.0.14 via the admincp.php?app=config tab parameter.
Published 2019-04-21 · Modified
6.1EPSS 0.008
CVE-2026-30661
iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.
Published 2026-03-24 · Analyzed
6.1EPSS 0.002
CVE-2019-8902
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
Published 2019-02-18 · Modified
5.7EPSS 0.004