github.com
https://github.com/CuppaCMS/CuppaCMS/issues/33 CVE-2022-38296
CRITICALNuclei
cuppacms cuppacms Unrestricted Upload of File with Dangerous Type
Record summary
CVE-2022-38296 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.
Description
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 7, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
cuppacmsBrowse cuppacms / cuppacms | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALCuppa CMS v1.0 - Arbitrary File UploadCVSS 9.8
Cuppa CMS v1.0 was discovered to contain an arbitrary file upload vulnerability via the File Manager.
Impact
Successful exploitation of this vulnerability can lead to remote code execution and compromise of the affected system.
Remediation
Apply the latest patch or upgrade to a newer version of Cuppa CMS to mitigate this vulnerability.
WeaknessesCWE-434
Authorstheamanrawat
Template tagscvecve2022rcecuppaintrusivecuppacmsvulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:cuppacms:cuppacms:1.0:*:*:*:*:*:*:*
https://github.com/CuppaCMS/CuppaCMS https://nvd.nist.gov/vuln/detail/CVE-2022-38296 https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-38296