📦 Kiwi Tcms

by Kiwitcms

🔍 What is Kiwi Tcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-32686

HIGH CVSS 8.1 May 27, 2023

CVE-2023-32686 is a cross-site scripting (XSS) vulnerability in Kiwi TCMS that allows attackers to bypass file upload validation and upload malicious files. When combined with other files, these can c...

CVE-2023-30613

HIGH CVSS 8.1 Apr 24, 2023

Kiwi TCMS versions before 12.2 allow unrestricted file uploads, enabling attackers to upload malicious files like executables or JavaScript-containing files. This could lead to remote code execution o...

CVE-2023-27489

HIGH CVSS 7.6 Mar 29, 2023

Kiwi TCMS versions before 12.1 are vulnerable to cross-site scripting (XSS) via malicious SVG file uploads. When users upload SVG files containing JavaScript and view them directly (not embedded in HT...

CVE-2023-25156

HIGH CVSS 7.5 Feb 15, 2023

Kiwi TCMS versions before 12.0 lack rate limiting on the login page, allowing attackers to perform brute-force attacks against user credentials. This affects all Kiwi TCMS deployments using vulnerable...