📦 Icecms

by Thecosy

🔍 What is Icecms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-46612

CRITICAL CVSS 9.8 Sep 25, 2024

IceCMS v3.4.7 and earlier contain a hardcoded JWT secret key, allowing attackers to forge authentication tokens and gain unauthorized access. This affects all deployments using vulnerable versions of ...

CVE-2025-22983

HIGH CVSS 7.5 Jan 14, 2025

An access control vulnerability in iceCMS v2.2.0 allows unauthenticated attackers to access sensitive information via the /square/getAllSquare/circle endpoint. This affects all deployments of iceCMS v...

CVE-2025-22984

HIGH CVSS 7.5 Jan 14, 2025

An unauthenticated access control vulnerability in iceCMS v2.2.0 allows attackers to access sensitive information via the /api/squareComment/DelectSquareById endpoint. This affects all deployments run...

CVE-2024-46607

HIGH CVSS 7.6 Sep 25, 2024

This vulnerability allows attackers to bypass authentication in IceCMS by entering any arbitrary values as username and password in the admin login endpoint. Any organization using IceCMS v3.4.7 or ea...

CVE-2024-46610

HIGH CVSS 7.5 Sep 25, 2024

An access control vulnerability in IceCMS v3.4.7 and earlier allows attackers to modify any user's information, including usernames and passwords, without proper authorization. This affects all IceCMS...