CVE-2014-9182: Anchorcms Anchor CMS

Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.

models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.

Affected products

  • Anchorcms Anchor CMS: up to and including 0.9.2; version 0.9.1 only

Published 2014-12-02. Last modified 2026-06-17.