📦 Foxcms

by Foxcms

🔍 What is Foxcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-50692

CRITICAL CVSS 9.8 Aug 7, 2025

FoxCMS versions up to 1.2.5 contain a code injection vulnerability in the admin template file editor that allows authenticated attackers to execute arbitrary code on the server. This affects all FoxCM...

CVE-2025-29306

CRITICAL CVSS 9.8 Mar 27, 2025

This vulnerability allows remote attackers to execute arbitrary code on FoxCMS v1.2.5 systems through the case display page in index.html. It affects all deployments of FoxCMS v1.2.5 that have the vul...

CVE-2025-25789

CRITICAL CVSS 9.8 Feb 26, 2025

FoxCMS v1.2.5 contains a critical remote code execution vulnerability in the index() method of the Sitemap controller. This allows unauthenticated attackers to execute arbitrary code on affected syste...

CVE-2025-56630

HIGH CVSS 7.3 Sep 8, 2025

FoxCMS v1.2.5 and earlier contains a SQL injection vulnerability in the column_model parameter of the admin controller. This allows attackers to execute arbitrary SQL commands on the database. All Fox...

CVE-2025-55422

HIGH CVSS 8.8 Aug 27, 2025

FoxCMS 1.2.6 contains a reflected Cross-Site Scripting (XSS) vulnerability in the /index.php/plus endpoint that allows attackers to inject malicious scripts into web pages. This affects all users of F...

CVE-2025-55409

HIGH CVSS 8.8 Aug 25, 2025

FoxCMS 1.2.6 contains a cross-site scripting (XSS) vulnerability in the /index.php/article endpoint that allows attackers to inject and execute malicious JavaScript code. This affects all FoxCMS 1.2.6...

CVE-2025-46154

HIGH CVSS 8.4 Jun 3, 2025

Foxcms v1.25 contains a SQL time-based injection vulnerability in the installdb.php file's dbname parameter. This allows attackers to execute arbitrary SQL queries by manipulating database connection ...

CVE-2025-29181

HIGH CVSS 7.2 Apr 17, 2025

FOXCMS versions up to 1.25 contain a SQL injection vulnerability in the admin panel's field management functionality. Attackers can inject malicious SQL queries through the title parameter, potentiall...

CVE-2025-56435

MEDIUM CVSS 5.3 Sep 3, 2025

A SQL injection vulnerability in FoxCMS v1.2.6 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter in /DataBackup.php. This could lead to unauthorized data acces...

CVE-2025-5155

MEDIUM CVSS 6.3 May 25, 2025

This critical SQL injection vulnerability in FoxCMS 1.2.5 allows remote attackers to execute arbitrary SQL commands via the 'ids' parameter in the batchCope function. Attackers can potentially read, m...

CVE-2025-12920

LOW CVSS 2.4 Nov 9, 2025

This is a cross-site scripting (XSS) vulnerability in FoxCMS up to version 1.2.16 that allows attackers to inject malicious scripts via the Title parameter in product add/edit functions. The vulnerabi...