cuppacms CVE Vulnerabilities & Metrics

Focus on cuppacms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About cuppacms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with cuppacms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total cuppacms CVEs: 25
Earliest CVE date: 21 Sep 2018, 07:29 UTC
Latest CVE date: 20 Dec 2023, 19:15 UTC

Latest CVE reference: CVE-2023-47990

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical cuppacms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.4

Max CVSS: 7.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 10
4.0-6.9 7
7.0-8.9 8
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS cuppacms CVEs

These are the five CVEs with the highest CVSS scores for cuppacms, sorted by severity first and recency.

All CVEs for cuppacms

CVE-2023-47990 cuppacms vulnerability CVSS: 0 20 Dec 2023, 19:15 UTC

SQL Injection vulnerability in components/table_manager/html/edit_admin_table.php in CuppaCMS V1.0 allows attackers to run arbitrary SQL commands via the table parameter.

CVE-2023-39681 cuppacms vulnerability CVSS: 0 05 Sep 2023, 18:15 UTC

Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.

CVE-2021-29368 cuppacms vulnerability CVSS: 0 20 Jan 2023, 19:15 UTC

Session fixation vulnerability in CuppaCMS thru commit 4c9b742b23b924cf4c1f943f48b278e06a17e297 on November 12, 2019 allows attackers to gain access to arbitrary user sessions.

CVE-2022-37191 cuppacms vulnerability CVSS: 0 13 Sep 2022, 23:15 UTC

The component "cuppa/api/index.php" of CuppaCMS v1.0 is Vulnerable to LFI. An authenticated user can read system files via crafted POST request using [function] parameter value as LFI payload.

CVE-2022-37190 cuppacms vulnerability CVSS: 0 13 Sep 2022, 23:15 UTC

CuppaCMS 1.0 is vulnerable to Remote Code Execution (RCE). An authenticated user can control both parameters (action and function) from "/api/index.php.

CVE-2022-38296 cuppacms vulnerability CVSS: 0 12 Sep 2022, 21:15 UTC

Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.

CVE-2022-38295 cuppacms vulnerability CVSS: 0 12 Sep 2022, 21:15 UTC

Cuppa CMS v1.0 was discovered to contain a cross-site scripting vulnerability at /table_manager/view/cu_user_groups. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Add New Group function.

CVE-2022-34121 cuppacms vulnerability CVSS: 0 27 Jul 2022, 18:15 UTC

Cuppa CMS v1.0 was discovered to contain a local file inclusion (LFI) vulnerability via the component /templates/default/html/windows/right.php.

CVE-2022-27985 cuppacms vulnerability CVSS: 7.5 26 Apr 2022, 14:15 UTC

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via /administrator/alerts/alertLightbox.php.

CVE-2022-27984 cuppacms vulnerability CVSS: 7.5 26 Apr 2022, 14:15 UTC

CuppaCMS v1.0 was discovered to contain a SQL injection vulnerability via the menu_filter parameter at /administrator/templates/default/html/windows/right.php.

CVE-2022-25498 cuppacms vulnerability CVSS: 7.5 15 Mar 2022, 18:15 UTC

CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.

CVE-2022-25497 cuppacms vulnerability CVSS: 5.0 15 Mar 2022, 18:15 UTC

CuppaCMS v1.0 was discovered to contain an arbitrary file read via the copy function.

CVE-2022-25495 cuppacms vulnerability CVSS: 7.5 15 Mar 2022, 18:15 UTC

The component /jquery_file_upload/server/php/index.php of CuppaCMS v1.0 allows attackers to upload arbitrary files and execute arbitrary code via a crafted PHP file.

CVE-2022-25486 cuppacms vulnerability CVSS: 6.8 15 Mar 2022, 18:15 UTC

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertConfigField.php.

CVE-2022-25485 cuppacms vulnerability CVSS: 6.8 15 Mar 2022, 18:15 UTC

CuppaCMS v1.0 was discovered to contain a local file inclusion via the url parameter in /alerts/alertLightbox.php.

CVE-2022-25401 cuppacms vulnerability CVSS: 5.0 24 Feb 2022, 15:15 UTC

The copy function of the file manager in Cuppa CMS v1.0 allows any file to be copied to the current directory, granting attackers read access to arbitrary files.

CVE-2022-24647 cuppacms vulnerability CVSS: 5.5 10 Feb 2022, 23:15 UTC

Cuppa CMS v1.0 was discovered to contain an arbitrary file deletion vulnerability via the unlink() function.

CVE-2022-24266 cuppacms vulnerability CVSS: 7.8 31 Jan 2022, 22:15 UTC

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the order_by parameter.

CVE-2022-24265 cuppacms vulnerability CVSS: 7.8 31 Jan 2022, 22:15 UTC

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/menu/ via the path=component/menu/&menu_filter=3 parameter.

CVE-2022-24264 cuppacms vulnerability CVSS: 7.8 31 Jan 2022, 22:15 UTC

Cuppa CMS v1.0 was discovered to contain a SQL injection vulnerability in /administrator/components/table_manager/ via the search_word parameter.

CVE-2021-3376 cuppacms vulnerability CVSS: 6.5 14 Dec 2021, 14:15 UTC

An issue was discovered in Cuppa CMS Versions Before 31 Jan 2021 allows authenticated attackers to gain escalated privileges via a crafted POST request using the user_group_id_field parameter.

CVE-2020-26048 cuppacms vulnerability CVSS: 6.5 05 Oct 2020, 15:15 UTC

The file manager option in CuppaCMS before 2019-11-12 allows an authenticated attacker to upload a malicious file within an image extension and through a custom request using the rename function provided by the file manager is able to modify the image extension into PHP resulting in remote arbitrary code execution.

CVE-2018-19918 cuppacms vulnerability CVSS: 3.5 31 Dec 2018, 15:29 UTC

CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI.

CVE-2018-19559 cuppacms vulnerability CVSS: 7.5 26 Nov 2018, 07:29 UTC

CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

CVE-2018-17300 cuppacms vulnerability CVSS: 3.5 21 Sep 2018, 07:29 UTC

Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.