CVE-2018-18260: Tuzitio Camaleon CMS

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version."

Affected products

  • Tuzitio Camaleon CMS: version 2.4.0 only

Published 2018-10-15. Last modified 2026-06-17.