genixcms CVE Vulnerabilities & Metrics

Focus on genixcms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About genixcms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with genixcms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total genixcms CVEs: 18
Earliest CVE date: 23 Mar 2015, 16:59 UTC
Latest CVE date: 26 Apr 2018, 14:29 UTC

Latest CVE reference: CVE-2017-14740

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical genixcms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.16

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 4
4.0-6.9 12
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS genixcms CVEs

These are the five CVEs with the highest CVSS scores for genixcms, sorted by severity first and recency.

All CVEs for genixcms

CVE-2017-14740 genixcms vulnerability CVSS: 3.5 26 Apr 2018, 14:29 UTC

Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.

CVE-2017-17431 genixcms vulnerability CVSS: 4.3 05 Dec 2017, 21:29 UTC

GeniXCMS 1.1.5 has XSS via the from, id, lang, menuid, mod, q, status, term, to, or token parameter. NOTE: this might overlap CVE-2017-14761, CVE-2017-14762, or CVE-2017-14765.

CVE-2017-14765 genixcms vulnerability CVSS: 4.3 27 Sep 2017, 08:29 UTC

In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.

CVE-2017-14764 genixcms vulnerability CVSS: 6.5 27 Sep 2017, 08:29 UTC

In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.

CVE-2017-14763 genixcms vulnerability CVSS: 6.5 27 Sep 2017, 08:29 UTC

In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.

CVE-2017-14762 genixcms vulnerability CVSS: 4.3 27 Sep 2017, 08:29 UTC

In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.

CVE-2017-14761 genixcms vulnerability CVSS: 4.3 27 Sep 2017, 08:29 UTC

In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.

CVE-2017-14231 genixcms vulnerability CVSS: 5.0 10 Sep 2017, 07:29 UTC

GeniXCMS before 1.1.0 allows remote attackers to cause a denial of service (account blockage) by leveraging the mishandling of certain username substring relationships, such as the admin<script> username versus the admin username, related to register.php, User.class.php, and Type.class.php.

CVE-2017-8827 genixcms vulnerability CVSS: 6.4 08 May 2017, 06:29 UTC

forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.

CVE-2017-8780 genixcms vulnerability CVSS: 3.5 04 May 2017, 14:29 UTC

GeniXCMS 1.0.2 has XSS triggered by a comment that is mishandled during a publish operation by an administrator, as demonstrated by a malformed P element.

CVE-2017-8762 genixcms vulnerability CVSS: 3.5 03 May 2017, 22:59 UTC

GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.

CVE-2017-8388 genixcms vulnerability CVSS: 5.0 01 May 2017, 16:59 UTC

GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.

CVE-2017-8377 genixcms vulnerability CVSS: 6.5 01 May 2017, 16:59 UTC

GeniXCMS 1.0.2 has SQL Injection in inc/lib/Control/Backend/menus.control.php via the menuid parameter.

CVE-2017-8376 genixcms vulnerability CVSS: 3.5 01 May 2017, 16:59 UTC

GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.

CVE-2017-5346 genixcms vulnerability CVSS: 6.5 12 Jan 2017, 06:59 UTC

SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.

CVE-2016-10096 genixcms vulnerability CVSS: 7.5 01 Jan 2017, 19:59 UTC

SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.

CVE-2015-2679 genixcms vulnerability CVSS: 7.5 23 Mar 2015, 16:59 UTC

Multiple SQL injection vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter to index.php or (2) username parameter to gxadmin/login.php.

CVE-2015-2678 genixcms vulnerability CVSS: 4.3 23 Mar 2015, 16:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in MetalGenix GeniXCMS before 0.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter in the categories page to gxadmin/index.php or (2) page parameter to index.php.