CVE-2023-30145: Tuzitio Camaleon CMS

Critical severity, CVSS 9.8. EPSS: 46.1% chance of exploitation in the next 30 days.

Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.

Affected products

  • Tuzitio Camaleon CMS: up to and including 2.7.0

Published 2023-05-26. Last modified 2026-06-17.