Clippercms
10 known vulnerabilities
Top Products
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the pkg_url parameter at /manager/in
ClipperCMS 1.3.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the rss_url_news parameter at /manag
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields
ClipperCMS 1.3.3 allows remote authenticated administrators to upload .htaccess files.
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
ClipperCMS 1.3.3 has stored XSS via the Full Name field of (1) Security -> Manager Users or (2) Security -> Web Users.
ClipperCMS 1.3.3 has stored XSS via the "Tools -> Configuration" screen of the manager/ URI.
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
ClipperCMS 1.3.3 allows Session Fixation.
Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in
Frequently Asked Questions
How many CVEs affect Clippercms?
Clippercms has 10 CVE records in our database, including 2 critical and 3 high severity vulnerabilities.
What are the most severe Clippercms vulnerabilities?
Clippercms has 2 critical severity (CVSS 9.0+) and 3 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Clippercms vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Clippercms products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Clippercms Vulnerabilities
CyberStrike scans your infrastructure for Clippercms vulnerabilities and provides real-time remediation guidance.
Get Started