CVE-2014-9182: Anchorcms Anchor CMS
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
models/comment.php in Anchor CMS 0.9.2 and earlier allows remote attackers to inject arbitrary headers into mail messages via a crafted Host: header.
Affected products
- Anchorcms Anchor CMS: up to and including 0.9.2; version 0.9.1 only
Published 2014-12-02. Last modified 2026-06-17.