CVE-2018-19559: Cuppacms

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.

Affected products

  • Cuppacms Cuppacms: before 2018-11-12 (fixed in 2018-11-12)

Published 2018-11-26. Last modified 2026-06-17.