Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Softaculous — Vulnerabilities & Security Advisories 42

Browse all 42 CVE security advisories affecting Softaculous. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Softaculous operates as an automated script installer for web hosting environments, enabling users to deploy applications like WordPress or Joomla with minimal manual configuration. Despite its utility, the platform has accumulated thirty-five recorded Common Vulnerabilities and Exposures, reflecting significant security challenges in its codebase. Historically, these flaws predominantly involve remote code execution, cross-site scripting, and privilege escalation vulnerabilities, often stemming from insufficient input validation or improper access controls within the installer scripts. These defects allow attackers to potentially compromise underlying server infrastructure or gain unauthorized administrative access to hosted applications. While no single catastrophic breach has been widely publicized as a direct result of these specific CVEs, the high volume of disclosed issues indicates persistent weaknesses in the software’s security architecture. This pattern necessitates rigorous patching and careful deployment practices for administrators relying on the tool.

CVE ID Title CVSS Severity Published
CVE-2024-5599 FileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory Listing — FileOrganizer – WordPress File Manager CWE-922 7.5 High 2024-06-07
CVE-2024-2324 FileOrganizer and FileOrganizer Pro <= 1.0.6 - Authenticated Stored Cross-Site Scripting — FileOrganizer – WordPress File Manager CWE-79 4.4 Medium 2024-05-02
CVE-2024-2504 Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.4 - Authenticated(Contributor+) Stored Cross-Site Scripting via custom attributes — Page Builder: Pagelayer – Drag and Drop website builder CWE-79 6.4 Medium 2024-04-09
CVE-2024-2294 Backuply – Backup, Restore, Migrate and Clone <= 1.2.7 - Authenticated (Admin+) Directory Traversal — Backuply – Backup, Restore, Migrate and Clone CWE-22 4.9 Medium 2024-03-16
CVE-2024-2127 Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes — Page Builder: Pagelayer – Drag and Drop website builder CWE-79 6.4 Medium 2024-03-07
CVE-2024-1590 Page Builder: Pagelayer – Drag and Drop website builder <= 1.8.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button — Page Builder: Pagelayer – Drag and Drop website builder CWE-79 4.6 Medium 2024-02-23
CVE-2024-0842 Backuply - Backup, Restore, Migrate and Clone <= 1.2.6 - Denial of Service — Backuply – Backup, Restore, Migrate and Clone CWE-400 7.5 High 2024-02-09
CVE-2024-0697 Backuply – Backup, Restore, Migrate and Clone <= 1.2.3 - Authenticated (Administrator+) Directory Traversal — Backuply – Backup, Restore, Migrate and Clone CWE-22 6.5 Medium 2024-01-27
CVE-2023-6598 SpeedyCache <= 1.1.3 - Missing Authorization to Plugin Options Update — SpeedyCache – Cache, Optimization, Performance CWE-862 4.3 Medium 2024-01-11
CVE-2023-6738 PageLayer <= 1.7.8 - Authenticated(Contributor+) Stored Cross-Site Scripting via meta fields — Page Builder: Pagelayer – Drag and Drop website builder CWE-20 5.4 Medium 2024-01-04
CVE-2022-45079 WordPress Loginizer Plugin <= 1.7.5 is vulnerable to Cross Site Request Forgery (CSRF) — Loginizer CWE-352 4.7 Medium 2023-05-22
CVE-2022-45084 WordPress Loginizer Plugin <= 1.7.5 is vulnerable to Cross Site Scripting (XSS) — Loginizer CWE-79 7.1 Medium 2023-04-24

This page lists every published CVE security advisory associated with Softaculous. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.