CVE Tools

Camaleon_cms

23 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Camaleon_cms, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Camaleon_cms CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Camaleon_cms CVEs per month
MonthCVEs
2024-101
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-031
2026-040
2026-050
2026-060
2026-070
2026-087
2026-091

Severity

How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical211%
  • High739%
  • Medium950%

Latest CVEs

The 15 most recently published vulnerabilities affecting Camaleon_cms.

  1. CVE-2026-86100Camaleon CMS 2.7.5 through 2.9.1 SSRF via HTTP Redirect in Upload from URL6.4
  2. CVE-2026-73326CamaleonCMS Missing Authorization via Plugin Administration Endpoints7.6
  3. CVE-2026-73332CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field8.7
  4. CVE-2026-73331CamaleonCMS 2.9.1 Authenticated SQL Injection via Post Slug Field7.1
  5. CVE-2026-73330CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action6.6
  6. CVE-2026-73329CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint8.7
  7. CVE-2026-56721CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController8.8
  8. CVE-2026-56720CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action4.3
  9. CVE-2026-1776Camaleon CMS AWS Uploader Authenticated Path Traversal Arbitrary File Read6.5
  10. CVE-2025-2304Camaleon CMS Privilege Escalation—
  11. CVE-2024-48652Cross Site Scripting vulnerability in camaleon-cms v.2.7.5 allows remote attacker to execute arbitrary code via the content group name field.4.8
  12. GHSA-75j2-9gmc-m855Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)—
  13. GHSA-8fx8-3rg2-79xwCamaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)—
  14. CVE-2024-46987Arbitrary path traversal in Camaleon CMS7.7
  15. CVE-2024-46986Arbitrary file write leading to RCE in Camaleon CMS9.9

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store