All 7 CVE vulnerabilities found in CamaleonCMS, with AI-generated Chinese analysis, references, and POCs.
Vendor: owen2345
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-73326 | CamaleonCMS Missing Authorization via Plugin Administration Endpoints CWE-862 | 7.6 | High | 2026-08-12 |
| CVE-2026-73332 | CamaleonCMS cama_contact_form Plugin Stored XSS via before_html Field CWE-89 | 8.7 | High | 2026-08-12 |
| CVE-2026-73331 | CamaleonCMS 2.9.1 Authenticated SQL Injection via Post Slug Field CWE-89 | 7.1 | High | 2026-08-12 |
| CVE-2026-73330 | CamaleonCMS 2.9.1 Server-Side Template Injection via test_email Action CWE-1336 | 6.6 | Medium | 2026-08-12 |
| CVE-2026-73329 | CamaleonCMS Stored XSS via Draft Post Title Creation Endpoint CWE-79 | 8.7 | High | 2026-08-12 |
| CVE-2026-56721 | CamaleonCMS 2.9.2 Privilege Escalation via Parameter Confusion in UsersController CWE-639 | 8.8 | High | 2026-08-11 |
| CVE-2026-56720 | CamaleonCMS 2.9.2 and earlier Missing Authorization via profile Action CWE-862 | 4.3 | Medium | 2026-08-11 |
All 7 known CVE vulnerabilities affecting CamaleonCMS with full Chinese analysis, references, and POCs where available.