ImpressCMS GitHub Repositoryproduct
https://github.com/ImpressCMS/impresscms CVE-2022-50912
CRITICAL
ImpressCMS 1.4.4 - Unrestricted File Upload
Record summary
CVE-2022-50912 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.
Description
ImpressCMS 1.4.4 contains a file upload vulnerability with weak extension sanitization that allows attackers to upload potentially malicious files. Attackers can bypass file upload restrictions by using alternative file extensions .php2.php6.php7.phps.pht to execute arbitrary PHP code on the server.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 14, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ImpressCMSBrowse ImpressCMS / ImpressCMS | CVE List | 1.4.4 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBImpressCMS v1.4.4 - Unrestricted File UploadExploitDB exploitby Ünsal Furkan HaraniNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-50912 ExploitDB-50890exploit
https://www.exploit-db.com/exploits/50890 Official ImpressCMS Homepageproduct
https://www.impresscms.org/ VulnCheck Advisory: ImpressCMS 1.4.4 - Unrestricted File UploadThird-party advisory
https://www.vulncheck.com/advisories/impresscms-unrestricted-file-upload