CVE-2017-7991: Exponentcms Exponent CMS

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.

Affected products

Published 2017-04-22. Last modified 2026-06-17.