kooboo has 2 CVEs on record. The median CVSS is 9.8 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.8
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Weakness classes
Products
- kooboo_cms 2
2
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
Worst active — by depth score
kooboo vulnerabilities
CVEs affecting kooboo, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2021-36582Critical· 9.8In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server
In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and ca…
▾ Midnightkooboo · kooboo_cmsEPSS 1.5%via NVD
CVE-2021-36581Critical· 9.8Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload
Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.
▾ Midnightkooboo · kooboo_cmsEPSS 1.4%via NVD