Skip to content
Noroxi

CouchCMS records

5 published records for vendor couchcms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

5 records
  • CVE-2018-7662
    35Monitor

    Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpm

    MediumCVSS 5.3Proof of conceptEPSS 47%

    couchcms · couchMar 4, 2018

  • CouchCMS Privilege Escalation via f_k_levels_list Parameter

    HighCVSS 8.6No exploitEPSS 1%

    couchcms · couchcmsApr 10, 2026

  • ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directorie

    MediumCVSS 6.5No exploitEPSS 6%

    couchcms · couchcmsJan 9, 2026

  • An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary w

    MediumCVSS 6.1No exploitEPSS 0%

    couchcms · couchcmsSep 11, 2023

  • CouchCMS reCAPTCHA config.example.php hard-coded key

    LowCVSS 2.9No exploitEPSS 0%

    couchcms · couchcmsDec 21, 2025