exponentcms CVE Vulnerabilities & Metrics

Focus on exponentcms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About exponentcms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with exponentcms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total exponentcms CVEs: 55
Earliest CVE date: 01 Nov 2011, 22:55 UTC
Latest CVE date: 17 Feb 2023, 18:15 UTC

Latest CVE reference: CVE-2021-32441

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical exponentcms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.36

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 22
7.0-8.9 33
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS exponentcms CVEs

These are the five CVEs with the highest CVSS scores for exponentcms, sorted by severity first and recency.

All CVEs for exponentcms

CVE-2021-32441 exponentcms vulnerability CVSS: 0 17 Feb 2023, 18:15 UTC

SQL Injection vulnerability in Exponent-CMS v.2.6.0 fixed in 2.7.0 allows attackers to gain access to sensitive information via the selectValue function in the expConfig class.

CVE-2022-23049 exponentcms vulnerability CVSS: 3.5 09 Feb 2022, 23:15 UTC

Exponent CMS 2.6.0patch2 allows an authenticated user to inject persistent JavaScript code on the "User-Agent" header when logging in. When an administrator user visits the "User Sessions" tab, the JavaScript will be triggered allowing an attacker to compromise the administrator session.

CVE-2022-23048 exponentcms vulnerability CVSS: 6.5 09 Feb 2022, 23:15 UTC

Exponent CMS 2.6.0patch2 allows an authenticated admin user to upload a malicious extension in the format of a ZIP file with a PHP file inside it. After upload it, the PHP file will be placed at "themes/simpletheme/{rce}.php" from where can be accessed in order to execute commands.

CVE-2022-23047 exponentcms vulnerability CVSS: 3.5 09 Feb 2022, 23:15 UTC

Exponent CMS 2.6.0patch2 allows an authenticated admin user to inject persistent JavaScript code inside the "Site/Organization Name","Site Title" and "Site Header" parameters while updating the site settings on "/exponentcms/administration/configure_site"

CVE-2016-9026 exponentcms vulnerability CVSS: 7.5 31 Dec 2020, 03:15 UTC

Exponent CMS before 2.6.0 has improper input validation in fileController.php.

CVE-2016-9025 exponentcms vulnerability CVSS: 7.5 31 Dec 2020, 03:15 UTC

Exponent CMS before 2.6.0 has improper input validation in purchaseOrderController.php.

CVE-2016-9023 exponentcms vulnerability CVSS: 7.5 31 Dec 2020, 03:15 UTC

Exponent CMS before 2.6.0 has improper input validation in cron/find_help.php.

CVE-2016-9022 exponentcms vulnerability CVSS: 7.5 31 Dec 2020, 03:15 UTC

Exponent CMS before 2.6.0 has improper input validation in usersController.php.

CVE-2016-9021 exponentcms vulnerability CVSS: 7.5 31 Dec 2020, 03:15 UTC

Exponent CMS before 2.6.0 has improper input validation in storeController.php.

CVE-2016-8900 exponentcms vulnerability CVSS: 7.5 24 May 2019, 17:29 UTC

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expTagController.php related to change_tags.

CVE-2016-8898 exponentcms vulnerability CVSS: 7.5 24 May 2019, 17:29 UTC

Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/ecommerce/controllers/cartController.php.

CVE-2016-8899 exponentcms vulnerability CVSS: 7.5 23 May 2019, 19:29 UTC

Exponent CMS version 2.3.9 suffers from a Object Injection vulnerability in framework/modules/core/controllers/expCatController.php related to change_cats.

CVE-2016-8897 exponentcms vulnerability CVSS: 7.5 23 May 2019, 19:29 UTC

Exponent CMS version 2.3.9 suffers from a sql injection vulnerability in framework/modules/help/controllers/helpController.php.

CVE-2016-7443 exponentcms vulnerability CVSS: 7.5 07 Mar 2018, 02:29 UTC

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

CVE-2017-18213 exponentcms vulnerability CVSS: 6.5 04 Mar 2018, 02:29 UTC

In Exponent CMS before 2.4.1 Patch #6, certain admin users can elevate their privileges.

CVE-2015-1177 exponentcms vulnerability CVSS: 4.3 28 Aug 2017, 15:29 UTC

Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.2.

CVE-2017-8085 exponentcms vulnerability CVSS: 4.3 24 Apr 2017, 14:59 UTC

In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.

CVE-2017-7991 exponentcms vulnerability CVSS: 7.5 22 Apr 2017, 01:59 UTC

Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.

CVE-2016-9087 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.

CVE-2016-9020 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/modules/help/controllers/helpController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.

CVE-2016-9019 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.

CVE-2016-7789 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.

CVE-2016-7788 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.

CVE-2016-7784 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.

CVE-2016-7783 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

CVE-2016-7782 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.

CVE-2016-7781 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.

CVE-2016-7780 exponentcms vulnerability CVSS: 7.5 07 Mar 2017, 16:59 UTC

SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.

CVE-2016-7565 exponentcms vulnerability CVSS: 7.5 13 Feb 2017, 18:59 UTC

install/index.php in Exponent CMS 2.3.9 allows remote attackers to execute arbitrary commands via shell metacharacters in the sc array parameter.

CVE-2016-7400 exponentcms vulnerability CVSS: 7.5 07 Feb 2017, 15:59 UTC

Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an activate_address address controller action, (2) title parameter in a show blog controller action, or (3) content_id parameter in a showComments expComment controller action.

CVE-2017-5879 exponentcms vulnerability CVSS: 7.5 06 Feb 2017, 15:59 UTC

An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src.

CVE-2016-2242 exponentcms vulnerability CVSS: 10.0 23 Jan 2017, 21:59 UTC

Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.

CVE-2015-8684 exponentcms vulnerability CVSS: 4.3 18 Jan 2017, 17:59 UTC

Exponent CMS before 2.3.7 does not properly restrict the types of files that can be uploaded, which allows remote attackers to conduct cross-site scripting (XSS) attacks and possibly have other unspecified impact as demonstrated by uploading a file with an .html extension, then accessing it via the elFinder functionality.

CVE-2015-8667 exponentcms vulnerability CVSS: 4.3 18 Jan 2017, 17:59 UTC

Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the Username/Email.

CVE-2016-7791 exponentcms vulnerability CVSS: 7.5 12 Jan 2017, 22:59 UTC

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which leads to arbitrary code execution.

CVE-2016-7790 exponentcms vulnerability CVSS: 7.5 12 Jan 2017, 22:59 UTC

Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.

CVE-2016-9481 exponentcms vulnerability CVSS: 7.5 29 Nov 2016, 23:59 UTC

In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter '$this->params['content_id']' used directly in SQL. Impact is a SQL injection.

CVE-2016-9287 exponentcms vulnerability CVSS: 7.5 15 Nov 2016, 11:59 UTC

In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter '$term' used directly in SQL. Impact is a SQL injection.

CVE-2016-9288 exponentcms vulnerability CVSS: 7.5 11 Nov 2016, 23:59 UTC

In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this: /navigation/DragnDropReRank/target/1.

CVE-2016-9286 exponentcms vulnerability CVSS: 5.0 11 Nov 2016, 22:59 UTC

framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI.

CVE-2016-9285 exponentcms vulnerability CVSS: 5.0 11 Nov 2016, 22:59 UTC

framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue.

CVE-2016-9284 exponentcms vulnerability CVSS: 5.0 11 Nov 2016, 22:59 UTC

getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string.

CVE-2016-9283 exponentcms vulnerability CVSS: 5.0 11 Nov 2016, 22:59 UTC

SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addContentToSearch/id/ and a trailing string, related to a "sef URL" issue.

CVE-2016-9282 exponentcms vulnerability CVSS: 5.0 11 Nov 2016, 22:59 UTC

SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database information via action=search&module=search with the search_string parameter.

CVE-2016-9272 exponentcms vulnerability CVSS: 6.4 11 Nov 2016, 11:59 UTC

A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.

CVE-2016-9242 exponentcms vulnerability CVSS: 6.5 07 Nov 2016, 11:59 UTC

Multiple SQL injection vulnerabilities in the update method in framework/modules/core/controllers/expRatingController.php in Exponent CMS 2.4.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) content_type or (2) subtype parameter.

CVE-2016-9184 exponentcms vulnerability CVSS: 5.0 04 Nov 2016, 10:59 UTC

In /framework/modules/core/controllers/expHTMLEditorController.php of Exponent CMS 2.4.0, untrusted input is used to construct a table name, and in the selectObject method in mysqli class, table names are wrapped with a character that common filters do not filter, allowing for SQL Injection. Impact is Information Disclosure.

CVE-2016-9183 exponentcms vulnerability CVSS: 5.0 04 Nov 2016, 10:59 UTC

In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of ' or " characters. Impact is Information Disclosure.

CVE-2016-9182 exponentcms vulnerability CVSS: 5.0 04 Nov 2016, 10:59 UTC

Exponent CMS 2.4 uses PHP reflection to call a method of a controller class, and then uses the method name to check user permission. But, the method name in PHP reflection is case insensitive, and Exponent CMS permits undefined actions to execute by default, so an attacker can use a capitalized method name to bypass the permission check, e.g., controller=expHTMLEditor&action=preview&editor=ckeditor and controller=expHTMLEditor&action=Preview&editor=ckeditor. An anonymous user will be rejected for the former but can access the latter.

CVE-2016-9135 exponentcms vulnerability CVSS: 5.0 03 Nov 2016, 10:59 UTC

Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/framework/modules/help/controllers/helpController.php" affecting the version parameter. Impact is Information Disclosure.

CVE-2016-9134 exponentcms vulnerability CVSS: 5.0 03 Nov 2016, 10:59 UTC

Exponent CMS 2.3.9 suffers from a SQL injection vulnerability in "/expPaginator.php" affecting the order parameter. Impact is Information Disclosure.

CVE-2016-7453 exponentcms vulnerability CVSS: 7.5 03 Nov 2016, 10:59 UTC

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to perform an fid SQL Injection.

CVE-2016-7452 exponentcms vulnerability CVSS: 5.0 03 Nov 2016, 10:59 UTC

The Pixidou Image Editor in Exponent CMS prior to v2.3.9 patch 2 could be used to upload a malicious file to any folder on the site via a cpi directory traversal.

CVE-2016-7095 exponentcms vulnerability CVSS: 7.5 03 Nov 2016, 10:59 UTC

Exponent CMS before 2.3.9 is vulnerable to an attacker uploading a malicious script file using redirection to place the script in an unprotected folder, one allowing script execution.

CVE-2014-8690 exponentcms vulnerability CVSS: 4.3 19 Feb 2015, 15:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, and 2.3.x before 2.3.1 patch 4 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, the (2) src parameter in a none action to index.php, or the (3) "First Name" or (4) "Last Name" field to users/edituser.

CVE-2013-3295 exponentcms vulnerability CVSS: 7.5 30 Dec 2014, 02:59 UTC

Directory traversal vulnerability in install/popup.php in Exponent CMS before 2.2.0 RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.

CVE-2014-6635 exponentcms vulnerability CVSS: 4.3 26 Oct 2014, 20:55 UTC

Cross-site scripting (XSS) vulnerability in Exponent CMS 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the src parameter in the search action to index.php.

CVE-2013-3294 exponentcms vulnerability CVSS: 7.5 11 Feb 2014, 17:55 UTC

Multiple SQL injection vulnerabilities in Exponent CMS before 2.2.0 release candidate 1 allow remote attackers to execute arbitrary SQL commands via the (1) src or (2) username parameter to index.php.

CVE-2010-5002 exponentcms vulnerability CVSS: 4.3 01 Nov 2011, 22:55 UTC

Cross-site scripting (XSS) vulnerability in modules/slideshowmodule/slideshow.js.php in Exponent CMS 0.97.0 allows remote attackers to inject arbitrary web script or HTML via the u parameter.