Schlix Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Schlix products.
Products
- Schlix CMS2 vulnerabilities
- cms1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-47964HIGH | Schlix CMS 2.2.6-6 Remote Code Execution via core.blockmanagerSchlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP file containing PHP code in the packageinfo.inc file and trigger execution by accessing the About tab of the installed extension. CWE-94May 15, 2026 | CVSS8.7v4.0 | EPSS0.71% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-47834MEDIUM | Schlix CMS 2.2.6-6 - 'title' Persistent Cross-Site Scripting (Authenticated)Schlix CMS 2.2.6-6 contains a persistent cross-site scripting vulnerability that allows authenticated users to inject malicious scripts into category titles. Attackers can create a new contact category with a script payload that will execute when the page is viewed by other users. CWE-79Jan 16, 2026 | CVSS5.1v4.0 | EPSS0.248% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-45544HIGH | Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to upload new executable PHP code, such as a theme that was obtained from a trusted source or was developed for their own website. Only an admin can upload such code, not someone else in an "attacker" role. CWE-863Feb 7, 2023 | CVSS8.8v3.1 | EPSS1.32% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |