Skip to content

Known CVE

ImpressCMS < 1.4.3 - SQL Injection

ImpressCMS before 1.4.3 is vulnerable to SQL injection via the groups parameter in include/findusers.php, allowing unauthenticated attackers to execute arbitrary SQL queries.

CVE-2021-26599

High2021CVSS 9.8CWE-89

cve2021 · impresscms · sqli · time-based-sqli · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website