CVE-2016-7443: Exponentcms Exponent CMS

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

Affected products

  • Exponentcms Exponent CMS: from 2.3.0, up to and including 2.3.9

Published 2018-03-07. Last modified 2026-06-17.