impresscms CVE Vulnerabilities & Metrics

Focus on impresscms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About impresscms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with impresscms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total impresscms CVEs: 11
Earliest CVE date: 04 Aug 2008, 19:41 UTC
Latest CVE date: 13 Jul 2023, 17:15 UTC

Latest CVE reference: CVE-2023-37785

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical impresscms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.62

Max CVSS: 10.0

Critical CVEs (≥9): 1

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 10
7.0-8.9 5
9.0-10.0 1

CVSS Distribution Chart

Top 5 Highest CVSS impresscms CVEs

These are the five CVEs with the highest CVSS scores for impresscms, sorted by severity first and recency.

All CVEs for impresscms

CVE-2023-37785 impresscms vulnerability CVSS: 0 13 Jul 2023, 17:15 UTC

A cross-site scripting (XSS) vulnerability in ImpressCMS v1.4.5 and before allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the smile_code parameter of the component /editprofile.php.

CVE-2022-26986 impresscms vulnerability CVSS: 8.5 05 Apr 2022, 15:15 UTC

SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this allows an attacker to read and modify the sensitive information from the database used by the application. If misconfigured, an attacker can even upload a malicious web shell to compromise the entire system.

CVE-2021-26601 impresscms vulnerability CVSS: 5.5 28 Mar 2022, 01:15 UTC

ImpressCMS before 1.4.3 allows libraries/image-editor/image-edit.php image_temp Directory Traversal.

CVE-2021-26600 impresscms vulnerability CVSS: 7.5 28 Mar 2022, 01:15 UTC

ImpressCMS before 1.4.3 has plugins/preloads/autologin.php type confusion with resultant Authentication Bypass (!= instead of !==).

CVE-2021-26599 impresscms vulnerability CVSS: 7.5 28 Mar 2022, 01:15 UTC

ImpressCMS before 1.4.3 allows include/findusers.php groups SQL Injection.

CVE-2021-26598 impresscms vulnerability CVSS: 5.0 28 Mar 2022, 01:15 UTC

ImpressCMS before 1.4.3 has Incorrect Access Control because include/findusers.php allows access by unauthenticated attackers (who are, by design, able to have a security token).

CVE-2022-24977 impresscms vulnerability CVSS: 7.5 14 Feb 2022, 12:15 UTC

ImpressCMS before 1.4.2 allows unauthenticated remote code execution via ...../// directory traversal in origName or imageName, leading to unsafe interaction with the CKEditor processImage.php script. The payload may be placed in PHP_SESSION_UPLOAD_PROGRESS when the PHP installation supports upload_progress.

CVE-2021-28088 impresscms vulnerability CVSS: 3.5 11 Mar 2021, 17:15 UTC

Cross-site scripting (XSS) in modules/content/admin/content.php in ImpressCMS profile 1.4.2 allows remote attackers to inject arbitrary web script or HTML parameters through the "Display Name" field.

CVE-2020-17551 impresscms vulnerability CVSS: 3.5 07 Oct 2020, 17:15 UTC

ImpressCMS 1.4.0 is affected by XSS in modules/system/admin.php which may result in arbitrary remote code execution.

CVE-2018-13983 impresscms vulnerability CVSS: 4.3 06 May 2019, 19:29 UTC

ImpressCMS 1.3.10 has XSS via the PATH_INFO to htdocs/install/index.php, htdocs/install/page_langselect.php, or htdocs/install/page_modcheck.php.

CVE-2014-1836 impresscms vulnerability CVSS: 6.4 01 Jul 2015, 14:59 UTC

Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

CVE-2014-4036 impresscms vulnerability CVSS: 4.3 11 Jun 2014, 14:55 UTC

Cross-site scripting (XSS) vulnerability in modules/system/admin.php in ImpressCMS 1.3.6.1 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a listimg action.

CVE-2012-0987 impresscms vulnerability CVSS: 6.0 06 Oct 2012, 21:55 UTC

Directory traversal vulnerability in edituser.php in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allows remote authenticated users to include and execute arbitrary local files via a .. (dot dot) in the icmsConfigPlugins[sanitizer_plugins][] parameter.

CVE-2012-0986 impresscms vulnerability CVSS: 4.3 06 Oct 2012, 21:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in ImpressCMS 1.2.x before 1.2.7 Final and 1.3.x before 1.3.1 Final allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) notifications.php, (2) modules/system/admin/images/browser.php, and (3) modules/content/admin/content.php.

CVE-2010-4616 impresscms vulnerability CVSS: 4.3 29 Dec 2010, 22:33 UTC

Cross-site scripting (XSS) vulnerability in modules/content/admin/content.php in ImpressCMS 1.2.3 Final, and possibly other versions before 1.2.4, allows remote attackers to inject arbitrary web script or HTML via the quicksearch_ContentContent parameter.

CVE-2010-4271 impresscms vulnerability CVSS: 7.5 17 Nov 2010, 01:00 UTC

SQL injection vulnerability in ImpressCMS before 1.2.3 RC2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2008-6360 impresscms vulnerability CVSS: 4.3 02 Mar 2009, 16:30 UTC

Cross-site scripting (XSS) vulnerability in the userranks feature in modules/system/admin.php in ImpressCMS 1.0.2 final allows remote attackers to inject arbitrary web script or HTML via the rank_title parameter. NOTE: some of these details are obtained from third party information.

CVE-2008-5964 impresscms vulnerability CVSS: 6.8 23 Jan 2009, 19:00 UTC

Session fixation vulnerability in Social ImpressCMS before 1.1.1 RC1 allows remote attackers to hijack web sessions by setting the PHPSESSID parameter.

CVE-2008-3453 impresscms vulnerability CVSS: 10.0 04 Aug 2008, 19:41 UTC

Multiple unspecified vulnerabilities in ImpressCMS 1.0 have unknown impact and attack vectors, related to modules/admin.php and "a few files."