VendorsTuzitiocamaleon_cmsall versions
Vulnerabilities

Tuzitio Camaleon CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-46986
Arbitrary file write leading to RCE in Camaleon CMS
Published 2024-09-18 · Modified
9.9EPSS 0.410
CVE-2023-30145
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
Published 2023-05-26 · Modified
9.81 PoCEPSS 0.461
CVE-2021-25970
Camaleon CMS - Insufficient Session Expiration after Password Change
Published 2021-10-20 · Modified
8.8EPSS 0.013
CVE-2024-46987
Arbitrary path traversal in Camaleon CMS
Published 2024-09-18 · Modified
7.71 PoCEPSS 0.146
CVE-2026-1776
Camaleon CMS AWS Uploader Authenticated Path Traversal Arbitrary File Read
Published 2026-03-09 · Analyzed
6.5EPSS 0.007
CVE-2018-18260
In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version."
Published 2018-10-15 · Modified
6.1EPSS 0.010
CVE-2021-25969
Camaleon CMS - Stored Cross-Site Scripting (XSS) in Comments
Published 2021-10-20 · Modified
6.1EPSS 0.008
CVE-2023-53936
Cameleon CMS 2.7.4 Authenticated Persistent Cross-Site Scripting via Post Creation
Published 2025-12-18 · Modified
5.1EPSS 0.002
CVE-2021-25972
Camaleon CMS - Server-Side Request Forgery (SSRF) in Media Upload Feature
Published 2021-10-20 · Modified
4.9EPSS 0.010
CVE-2024-48652
Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.
Published 2024-10-22 · Analyzed
4.8EPSS 0.010
CVE-2021-25971
Camaleon CMS - SVG File Upload Creates DoS for Media Upload Feature
Published 2021-10-20 · Modified
4.3EPSS 0.010