Vulnerabilities
Vulnerable Software
Idreamsoft:  >> Icms  >> 8.0.0  Security Vulnerabilities
iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.
CVSS Score
6.1
EPSS Score
0.002
Published
2026-03-24
A vulnerability was detected in iCMS up to 8.0.0. Affected is the function Save of the file app/config/ConfigAdmincp.php of the component POST Parameter Handler. The manipulation of the argument config results in code injection. The attack can be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
2.0
EPSS Score
0.005
Published
2025-12-31
In iCMS <=8.0.0, a directory traversal vulnerability allows an attacker to read arbitrary files.
CVSS Score
7.5
EPSS Score
0.016
Published
2022-02-04
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
CVSS Score
9.8
EPSS Score
0.022
Published
2022-02-04


Contact Us

Shodan ® - All rights reserved