CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CouchCMS 2.2.1 contains a server-side request forgery vulnerability that allows authenticated attackers to make arbitrary HTTP requests by uploading malicious SVG files. Attackers can upload SVG files containing external entity references through the browse.php endpoint to access internal services and resources. | |
| Title | CouchCMS 2.2.1 Server-Side Request Forgery via SVG upload | |
| First Time appeared |
Couchcms
Couchcms couchcms |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:couchcms:couchcms:1.3.5:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:1.4.5:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:1.4.7:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:1.4:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.0:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.1:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.2.1:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.2:*:*:*:*:*:*:* cpe:2.3:a:couchcms:couchcms:2.3:*:*:*:*:*:*:* |
|
| Vendors & Products |
Couchcms
Couchcms couchcms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-15T18:36:26.824Z
Reserved: 2026-02-01T11:24:18.720Z
Link: CVE-2021-47958
No data.
Status : Received
Published: 2026-05-15T19:16:54.623
Modified: 2026-05-15T19:16:54.623
Link: CVE-2021-47958
No data.
OpenCVE Enrichment
No data.
Weaknesses