{"schema_version":1,"title":"camaleon_cms (RubyGems) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 19 vulnerabilities in camaleon_cms (RubyGems): 0 in the last 7 days and 2 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86100, was published on 5 September 2026.","url":"https://junglewise.ai/threats/technologies/camaleon-cms","json_url":"https://junglewise.ai/threats/technologies/camaleon-cms.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/camaleon-cms","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":19,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":1,"last_90_days":2,"last_365_days":4},"latest":[{"cve":"CVE-2026-86100","cvss":6.4,"epss":0.0032,"slug":"cve-2026-86100-camaleon-cms-server-side-request-forgery-in-upload-from-url","title":"Camaleon CMS server-side request forgery in upload from URL","severity":"medium","exploited":false,"published_at":"2026-09-05T00:17:20.81+00:00","url":"https://junglewise.ai/threats/cve-2026-86100-camaleon-cms-server-side-request-forgery-in-upload-from-url"},{"cve":"CVE-2026-66748","cvss":8.8,"slug":"cve-2026-66748-camaleon-cms-remote-code-execution-in-select-eval-custom-field","title":"Camaleon CMS remote code execution in select_eval custom field","severity":"high","exploited":false,"published_at":"2026-07-28T16:20:16.31+00:00","url":"https://junglewise.ai/threats/cve-2026-66748-camaleon-cms-remote-code-execution-in-select-eval-custom-field"},{"cve":"CVE-2026-10715","cvss":5.1,"slug":"cve-2026-10715-camaleon-cms-improper-authorization-in-draft-autosave-endpoint","title":"Camaleon CMS improper authorization in draft autosave endpoint","severity":"info","exploited":false,"published_at":"2026-06-12T19:16:25.387+00:00","url":"https://junglewise.ai/threats/cve-2026-10715-camaleon-cms-improper-authorization-in-draft-autosave-endpoint"},{"cve":"CVE-2026-1776","cvss":6.5,"epss":0.0073,"slug":"cve-2026-1776-camaleon-cms-path-traversal-in-aws-s3-uploader","title":"Camaleon CMS path traversal in AWS S3 uploader","severity":"medium","exploited":false,"published_at":"2026-03-10T07:38:01.95+00:00","url":"https://junglewise.ai/threats/cve-2026-1776-camaleon-cms-path-traversal-in-aws-s3-uploader"},{"cve":"CVE-2025-2304","cvss":4,"epss":0.0062,"slug":"cve-2025-2304-camaleon-cms-vulnerable-to-privilege-escalation-through-a-mass","title":"Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment","severity":"medium","exploited":false,"published_at":"2025-03-14T15:32:03+00:00","url":"https://junglewise.ai/threats/cve-2025-2304-camaleon-cms-vulnerable-to-privilege-escalation-through-a-mass"},{"cve":"CVE-2024-48652","cvss":3.1,"epss":0.0103,"slug":"cve-2024-48652-camaleon-cms-affected-by-cross-site-scripting","title":"camaleon_cms affected by cross site scripting","severity":"low","exploited":false,"published_at":"2024-10-23T00:31:45+00:00","url":"https://junglewise.ai/threats/cve-2024-48652-camaleon-cms-affected-by-cross-site-scripting"},{"cvss":3.1,"slug":"camaleon-cms-vulnerable-to-stored-xss-through-user-file-upload-ghsl-0a6a9b46","title":"Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)","severity":"low","exploited":false,"published_at":"2024-09-25T21:53:27+00:00","url":"https://junglewise.ai/threats/camaleon-cms-vulnerable-to-stored-xss-through-user-file-upload-ghsl-0a6a9b46"},{"cvss":3.1,"slug":"camaleon-cms-vulnerable-to-stored-xss-through-user-file-upload-ghsl-15da3087","title":"Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)","severity":"low","exploited":false,"published_at":"2024-09-23T22:10:33+00:00","url":"https://junglewise.ai/threats/camaleon-cms-vulnerable-to-stored-xss-through-user-file-upload-ghsl-15da3087"},{"slug":"duplicate-advisory-camaleon-cms-vulnerable-to-remote-code-execution-4aed8853","title":"Duplicate Advisory: Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)","severity":"info","exploited":false,"published_at":"2024-09-23T22:05:58+00:00","url":"https://junglewise.ai/threats/duplicate-advisory-camaleon-cms-vulnerable-to-remote-code-execution-4aed8853"},{"cvss":3.1,"slug":"camaleon-cms-vulnerable-to-remote-code-execution-through-code-injection-6be81aaf","title":"Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185)","severity":"low","exploited":false,"published_at":"2024-09-18T15:47:07+00:00","url":"https://junglewise.ai/threats/camaleon-cms-vulnerable-to-remote-code-execution-through-code-injection-6be81aaf"},{"cvss":3.1,"slug":"camaleon-cms-vulnerable-to-stored-xss-through-user-file-upload-ghsl-941d91af","title":"Camaleon CMS vulnerable to stored XSS through user file upload (GHSL-2024-184)","severity":"low","exploited":false,"published_at":"2024-09-18T15:47:01+00:00","url":"https://junglewise.ai/threats/camaleon-cms-vulnerable-to-stored-xss-through-user-file-upload-ghsl-941d91af"},{"cve":"CVE-2024-46987","cvss":3.1,"epss":0.1456,"slug":"cve-2024-46987-camaleon-cms-vulnerable-to-arbitrary-path-traversal-ghsl-2024-183","title":"Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)","severity":"low","exploited":false,"published_at":"2024-09-18T15:46:53+00:00","url":"https://junglewise.ai/threats/cve-2024-46987-camaleon-cms-vulnerable-to-arbitrary-path-traversal-ghsl-2024-183"},{"cve":"CVE-2024-46986","cvss":3.1,"epss":0.4096,"slug":"cve-2024-46986-camaleon-cms-affected-by-arbitrary-file-write-to-rce-ghsl-2024","title":"Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)","severity":"low","exploited":false,"published_at":"2024-09-18T14:39:03+00:00","url":"https://junglewise.ai/threats/cve-2024-46986-camaleon-cms-affected-by-arbitrary-file-write-to-rce-ghsl-2024"},{"cve":"CVE-2023-30145","cvss":3.1,"epss":0.4614,"slug":"cve-2023-30145-server-side-template-injection-in-camaleon-cms","title":"Server-Side Template Injection in Camaleon CMS","severity":"low","exploited":false,"published_at":"2023-05-26T15:30:21+00:00","url":"https://junglewise.ai/threats/cve-2023-30145-server-side-template-injection-in-camaleon-cms"},{"cve":"CVE-2021-25969","cvss":3.1,"epss":0.0081,"slug":"cve-2021-25969-camaleon-cms-stored-cross-site-scripting-vulnerability","title":"Camaleon CMS Stored Cross-site Scripting vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T22:33:54+00:00","url":"https://junglewise.ai/threats/cve-2021-25969-camaleon-cms-stored-cross-site-scripting-vulnerability"},{"cve":"CVE-2021-25970","cvss":3.1,"epss":0.0131,"slug":"cve-2021-25970-camaleon-cms-insufficient-session-expiration-vulnerability","title":"Camaleon CMS Insufficient Session Expiration vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T22:28:10+00:00","url":"https://junglewise.ai/threats/cve-2021-25970-camaleon-cms-insufficient-session-expiration-vulnerability"},{"cve":"CVE-2021-25971","cvss":3.1,"epss":0.0101,"slug":"cve-2021-25971-camaleon-cms-vulnerable-to-uncaught-exception","title":"Camaleon CMS vulnerable to Uncaught Exception","severity":"low","exploited":false,"published_at":"2022-05-24T19:18:05+00:00","url":"https://junglewise.ai/threats/cve-2021-25971-camaleon-cms-vulnerable-to-uncaught-exception"},{"cve":"CVE-2021-25972","cvss":3.1,"epss":0.0099,"slug":"cve-2021-25972-camaleon-cms-vulnerable-to-server-side-request-forgery","title":"Camaleon CMS vulnerable to Server-Side Request Forgery","severity":"low","exploited":false,"published_at":"2022-05-24T19:18:04+00:00","url":"https://junglewise.ai/threats/cve-2021-25972-camaleon-cms-vulnerable-to-server-side-request-forgery"},{"cve":"CVE-2018-18260","cvss":3,"epss":0.0105,"slug":"cve-2018-18260-camaleon-cms-vulnerable-to-stored-cross-site-scripting","title":"Camaleon CMS vulnerable to Stored Cross-site Scripting","severity":"low","exploited":false,"published_at":"2022-05-13T01:05:37+00:00","url":"https://junglewise.ai/threats/cve-2018-18260-camaleon-cms-vulnerable-to-stored-cross-site-scripting"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"nokogiri (RubyGems)","slug":"nokogiri","vulnerabilities":73,"url":"https://junglewise.ai/threats/technologies/nokogiri"},{"name":"rack (RubyGems)","slug":"rack","vulnerabilities":20,"url":"https://junglewise.ai/threats/technologies/rack"},{"name":"rails-html-sanitizer (RubyGems)","slug":"rails-html-sanitizer","vulnerabilities":19,"url":"https://junglewise.ai/threats/technologies/rails-html-sanitizer"},{"name":"actionpack (RubyGems)","slug":"actionpack","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/actionpack"},{"name":"publify_core (RubyGems)","slug":"publify-core","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/publify-core"},{"name":"rubygems-update (RubyGems)","slug":"rubygems-update","vulnerabilities":15,"url":"https://junglewise.ai/threats/technologies/rubygems-update"},{"name":"loofah (RubyGems)","slug":"loofah","vulnerabilities":14,"url":"https://junglewise.ai/threats/technologies/loofah"},{"name":"fat_free_crm (RubyGems)","slug":"fat-free-crm","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/fat-free-crm"},{"name":"passenger (RubyGems)","slug":"passenger","vulnerabilities":12,"url":"https://junglewise.ai/threats/technologies/passenger"},{"name":"oj (RubyGems)","slug":"oj","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/oj"},{"name":"openc3 (RubyGems)","slug":"openc3","vulnerabilities":10,"url":"https://junglewise.ai/threats/technologies/openc3"},{"name":"jquery-rails (RubyGems)","slug":"jquery-rails","vulnerabilities":9,"url":"https://junglewise.ai/threats/technologies/jquery-rails"}],"technology":{"hub":true,"name":"camaleon_cms (RubyGems)","slug":"camaleon-cms","vendor":{"name":"RubyGems","slug":"rubygems","url":"https://junglewise.ai/threats/vendors/rubygems"},"aliases":[],"homepage":"https://camaleon.wpicms.com/","repo_url":"https://github.com/owen2345/camaleon-cms","description":"A content management system for Ruby on Rails applications.","url":"https://junglewise.ai/threats/technologies/camaleon-cms"},"most_severe":[{"cve":"CVE-2026-66748","cvss":8.8,"slug":"cve-2026-66748-camaleon-cms-remote-code-execution-in-select-eval-custom-field","title":"Camaleon CMS remote code execution in select_eval custom field","severity":"high","exploited":false,"published_at":"2026-07-28T16:20:16.31+00:00","url":"https://junglewise.ai/threats/cve-2026-66748-camaleon-cms-remote-code-execution-in-select-eval-custom-field"},{"cve":"CVE-2026-1776","cvss":6.5,"epss":0.0073,"slug":"cve-2026-1776-camaleon-cms-path-traversal-in-aws-s3-uploader","title":"Camaleon CMS path traversal in AWS S3 uploader","severity":"medium","exploited":false,"published_at":"2026-03-10T07:38:01.95+00:00","url":"https://junglewise.ai/threats/cve-2026-1776-camaleon-cms-path-traversal-in-aws-s3-uploader"},{"cve":"CVE-2026-86100","cvss":6.4,"epss":0.0032,"slug":"cve-2026-86100-camaleon-cms-server-side-request-forgery-in-upload-from-url","title":"Camaleon CMS server-side request forgery in upload from URL","severity":"medium","exploited":false,"published_at":"2026-09-05T00:17:20.81+00:00","url":"https://junglewise.ai/threats/cve-2026-86100-camaleon-cms-server-side-request-forgery-in-upload-from-url"},{"cve":"CVE-2025-2304","cvss":4,"epss":0.0062,"slug":"cve-2025-2304-camaleon-cms-vulnerable-to-privilege-escalation-through-a-mass","title":"Camaleon CMS Vulnerable to Privilege Escalation through a Mass Assignment","severity":"medium","exploited":false,"published_at":"2025-03-14T15:32:03+00:00","url":"https://junglewise.ai/threats/cve-2025-2304-camaleon-cms-vulnerable-to-privilege-escalation-through-a-mass"},{"cve":"CVE-2023-30145","cvss":3.1,"epss":0.4614,"slug":"cve-2023-30145-server-side-template-injection-in-camaleon-cms","title":"Server-Side Template Injection in Camaleon CMS","severity":"low","exploited":false,"published_at":"2023-05-26T15:30:21+00:00","url":"https://junglewise.ai/threats/cve-2023-30145-server-side-template-injection-in-camaleon-cms"},{"cve":"CVE-2024-46986","cvss":3.1,"epss":0.4096,"slug":"cve-2024-46986-camaleon-cms-affected-by-arbitrary-file-write-to-rce-ghsl-2024","title":"Camaleon CMS affected by arbitrary file write to RCE (GHSL-2024-182)","severity":"low","exploited":false,"published_at":"2024-09-18T14:39:03+00:00","url":"https://junglewise.ai/threats/cve-2024-46986-camaleon-cms-affected-by-arbitrary-file-write-to-rce-ghsl-2024"},{"cve":"CVE-2024-46987","cvss":3.1,"epss":0.1456,"slug":"cve-2024-46987-camaleon-cms-vulnerable-to-arbitrary-path-traversal-ghsl-2024-183","title":"Camaleon CMS vulnerable to arbitrary path traversal (GHSL-2024-183)","severity":"low","exploited":false,"published_at":"2024-09-18T15:46:53+00:00","url":"https://junglewise.ai/threats/cve-2024-46987-camaleon-cms-vulnerable-to-arbitrary-path-traversal-ghsl-2024-183"},{"cve":"CVE-2021-25970","cvss":3.1,"epss":0.0131,"slug":"cve-2021-25970-camaleon-cms-insufficient-session-expiration-vulnerability","title":"Camaleon CMS Insufficient Session Expiration vulnerability","severity":"low","exploited":false,"published_at":"2022-05-24T22:28:10+00:00","url":"https://junglewise.ai/threats/cve-2021-25970-camaleon-cms-insufficient-session-expiration-vulnerability"},{"cve":"CVE-2024-48652","cvss":3.1,"epss":0.0103,"slug":"cve-2024-48652-camaleon-cms-affected-by-cross-site-scripting","title":"camaleon_cms affected by cross site scripting","severity":"low","exploited":false,"published_at":"2024-10-23T00:31:45+00:00","url":"https://junglewise.ai/threats/cve-2024-48652-camaleon-cms-affected-by-cross-site-scripting"},{"cve":"CVE-2021-25971","cvss":3.1,"epss":0.0101,"slug":"cve-2021-25971-camaleon-cms-vulnerable-to-uncaught-exception","title":"Camaleon CMS vulnerable to Uncaught Exception","severity":"low","exploited":false,"published_at":"2022-05-24T19:18:05+00:00","url":"https://junglewise.ai/threats/cve-2021-25971-camaleon-cms-vulnerable-to-uncaught-exception"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}