This page aggregates publicly disclosed CVE and security risk information related to icms_content_management_systems, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2005-4397 | SQL injection vulnerability in RunScript.asp iCMS allows remote attackers to execute arbitrary SQL commands via the Event_ID parameter. | [email protected] | 7.5 | 0.40% | 2005-12-20 | 2026-04-16 |
| CVE-2005-4396 | Cross-site scripting (XSS) vulnerability in admin/Default.asp in iCMS allows remote attackers to inject arbitrary web script or HTML via the LoginMSG parameter. NOTE: the provenance of this issue is unknown; the details were obtained solely from third party sources. | [email protected] | 4.3 | 0.28% | 2005-12-20 | 2026-04-16 |
| CVE-2005-3574 | PHP file inclusion vulnerability in index.php of iCMS allows remote attackers to include arbitrary files via the page parameter. | [email protected] | 5.0 | 0.50% | 2005-11-16 | 2026-04-16 |