CouchCMS records
5 published records for vendor couchcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-320 Key Management Errors1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-7662Proof of concept | Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpmcouchcms · couch · CWE-200 | Medium5.3 | — | 47.1% | Mar 4, 2018 |
34Monitor | CVE-2026-29002No exploit | CouchCMS Privilege Escalation via f_k_levels_list Parametercouchcms · couchcms · CWE-639 | High8.6 | — | 0.7% | Apr 10, 2026 |
28Monitor | CVE-2025-67004No exploit | ** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directoriecouchcms · couchcms · CWE-22 | Medium6.5 | — | 6.1% | Jan 9, 2026 |
24Monitor | CVE-2023-41609No exploit | An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary wcouchcms · couchcms · CWE-601 | Medium6.1 | — | 0.4% | Sep 11, 2023 |
11Monitor | CVE-2025-15005No exploit | CouchCMS reCAPTCHA config.example.php hard-coded keycouchcms · couchcms · CWE-320 | Low2.9 | — | 0.5% | Dec 21, 2025 |
- CVE-2018-766235Monitor
Couch through 2.0 allows remote attackers to discover the full path via a direct request to includes/mysql2i/mysql2i.func.php or addons/phpm
MediumCVSS 5.3Proof of conceptEPSS 47%couchcms · couchMar 4, 2018
- CVE-2026-2900234Monitor
CouchCMS Privilege Escalation via f_k_levels_list Parameter
HighCVSS 8.6No exploitEPSS 1%couchcms · couchcmsApr 10, 2026
- CVE-2025-6700428Monitor
** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via traversing directorie
MediumCVSS 6.5No exploitEPSS 6%couchcms · couchcmsJan 9, 2026
- CVE-2023-4160924Monitor
An open redirect vulnerability in the sanitize_url() parameter of CouchCMS v2.3 allows attackers to redirect a victim user to an arbitrary w
MediumCVSS 6.1No exploitEPSS 0%couchcms · couchcmsSep 11, 2023
- CVE-2025-1500511Monitor
CouchCMS reCAPTCHA config.example.php hard-coded key
LowCVSS 2.9No exploitEPSS 0%couchcms · couchcmsDec 21, 2025