CVE-2018-16731: Chshcms Cscms

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

Affected products

Published 2018-09-08. Last modified 2026-06-17.