Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Camaleon Cms MEDIUM 6.5
CVE-2026-1776

Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation th…

Fix: after 2.9.0
Fix from $1,600 2026-03-10
Camaleon Cms CRITICAL 9.9
CVE-2024-46986EPSS 37%

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. An arbitrary file write vulnerability accessible via the upl…

Fix: 2.8.2+
Fix from $2,300 2024-09-18
Camaleon Cms HIGH 7.7
CVE-2024-46987EPSS 15%

Camaleon CMS is a dynamic and advanced content management system based on Ruby on Rails. A path traversal vulnerability accessible via MediaControlle…

Fix: 2.8.2+
Fix from $1,950 2024-09-18
Camaleon Cms CRITICAL 9.8
CVE-2023-30145EPSS 46%

Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

Fix: after 2.7.0
Fix from $2,300 2023-05-26
Camaleon Cms HIGH 8.8
CVE-2021-25970

Camaleon CMS 0.1.7 to 2.6.0 doesn’t terminate the active session of the users, even after the admin changes the user’s password. A user that was alre…

Fix: after 2.6.0
Fix from $1,950 2021-10-20
Camaleon Cms MEDIUM 6.1
CVE-2021-25969

In Camaleon CMS application, versions 0.0.1 to 2.6.0 are vulnerable to stored XSS, that allows an unauthenticated attacker to store malicious scripts…

Fix: after 2.6.0
Fix from $1,600 2021-10-20
Camaleon Cms MEDIUM 6.1
CVE-2018-18260

In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload …

No fix yet
Fix from $1,600 2018-10-15