VendorsiDreamSofticmsany version
Vulnerabilities

iDreamSoft iCMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-44978
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
Published 2022-02-04 · Modified
9.8EPSS 0.022
CVE-2021-44977
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
Published 2022-02-04 · Modified
7.5EPSS 0.016
CVE-2025-15394
iCMS POST Parameter ConfigAdmincp.php save code injection
Published 2025-12-31 · Analyzed
7.2EPSS 0.005
CVE-2019-8902
An issue was discovered in idreamsoft iCMS through 7.0.14. A CSRF vulnerability can delete users' articles via the public/api.php?app=user URI.
Published 2019-02-18 · Modified
5.7EPSS 0.004