📦 Croogo

by Croogo

🔍 What is Croogo?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-29643

CRITICAL CVSS 9.1 Apr 18, 2025

This vulnerability allows attackers to perform Host header injection in Croogo v3.0.2 via the feed.rss component. Attackers can manipulate HTTP Host headers to redirect users to malicious sites, perfo...

CVE-2021-44673

HIGH CVSS 8.8 Mar 10, 2022

This vulnerability allows remote attackers to upload malicious web shell scripts through the file manager in Croogo CMS, leading to remote code execution. It affects Croogo 3.0.2 installations with th...

CVE-2024-42718

MEDIUM CVSS 6.5 Dec 26, 2025

This path traversal vulnerability in Croogo CMS 4.0.7 allows remote attackers to read arbitrary files on the server by manipulating the 'edit-file' parameter. Attackers can access sensitive files like...