Official Product Homepageproduct
https://github.com/CouchCMS/CouchCMS CVE-2021-47958
MEDIUM
CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload
Record summary
CVE-2021-47958 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 15, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
CouchCMSBrowse CouchCMS / CouchCMS | CVE List | 2.2.1 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCouchCMS 2.2.1 - Server-Side Request ForgeryExploitDB exploitby xxcddNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47958 ExploitDB-49675exploit
https://www.exploit-db.com/exploits/49675 VulnCheck Advisory: CouchCMS 2.2.1 Server-Side Request Forgery via SVG uploadThird-party advisory
https://www.vulncheck.com/advisories/couchcms-server-side-request-forgery-via-svg-upload