📦

cms

Vendor: schlix

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 3 Remote Access
Total CVEs 5 Total Indexed
Avg. EPSS 1.22% Exploit Prob.
Latest CVE CVE-2025-67443 Dec 22

Security Vulnerability Index

Page 1 / 1
6.1 CVSS

Schlix CMS before v2.2.9-5 is vulnerable to Cross Site Scripting (XSS). Due to lack of javascript sanitization in the login form, incorrect login attempts in logs are triggered as XSS in the admin panel.

EPSS: 0.16%
7.2 CVSS

An arbitrary file upload vulnerability in Schlix CMS v2.2.8-1, allows remote authenticated attackers to execute arbitrary code and obtain sensitive information via a crafted .phtml file.

EPSS: 1.16%
8.8 CVSS
CVE-2022-45544
RCE Exploit Found

Insecure Permission vulnerability in Schlix Web Inc SCHLIX CMS 2.2.7-2 allows attacker to upload arbitrary files and execute arbitrary code via the tristao parameter. NOTE: this is disputed by the vendor because an admin is intentionally allowed to upload new executable PHP code, such as a theme that was obtained from a trusted source or was developed for their own website. Only an admin can upload such code, not someone else in an "attacker" role.

EPSS: 1.32%
7.2 CVSS

admin/app/mediamanager in Schlix CMS 2.1.8-7 allows Authenticated Unrestricted File Upload, leading to remote code execution. NOTE: "While inadvertently allowing a PHP file to be uploaded via Media Manager was an oversight, it still requires an admin permission. We think it's pretty rare for an administrator to exploit a bug on his/her own site to own his/her own site.

EPSS: 2.24%