Vendor Products CVEs KEV Avg EPSS Worst Severity 1 4 0 43.2% HIGH
CVE ID Description Severity CVSS KEV EPSS Published CVE-2025-46041 A stored cross-site scripting (XSS) vulnerability in Anchor CMS v0.12.7 allows attackers to inject malicious JavaScript via the page description field in the page creation interface (/admin/pages/add). MEDIUM 5.4 — 43.2% Jun 9, 2025 CVE-2024-37732 Cross Site Scripting vulnerability in Anchor CMS v.0.12.7 allows a remote attacker to execute arbitrary code via a crafted .pdf file. MEDIUM 6.1 — — Jun 24, 2024 CVE-2024-29499 Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/users/delete/2. HIGH 7.4 — — Mar 22, 2024 CVE-2024-29338 Anchor CMS v0.12.7 was discovered to contain a Cross-Site Request Forgery (CSRF) via /anchor/admin/categories/delete/2. LOW 2.4 — — Mar 22, 2024