Skip to content
COOEY

FAIL › dossier

ecisp

VENDOR

· dossier confidence 50%

ECISP is a software vendor with a critical security track record, evidenced by three simultaneous RCE vulnerabilities in November 2022.

PROFILE
CategorySoftware VendorWhat they doECISP is a software vendor specializing in ESPCMS components, including input validation and file handling modules.
SECURITY POSTURE

Critical vulnerabilities in ESPCMS components were disclosed in November 2022, including three distinct Remote Code Execution (RCE) flaws.

Notable failures
  • CVE-2022-44088: RCE in INPUT_ISDESCRIPTION
  • CVE-2022-44089: RCE in IS_GETCACHE
  • CVE-2022-44087: RCE in UPFILE_PIC_ZOOM_HIGHT
Patterns: Multiple critical RCE vulnerabilities in same component version
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-11-10 CVE-2022-44088 critical ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
2022-11-10 CVE-2022-44089 critical ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
2022-11-10 CVE-2022-44087 critical ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
Open questions: Company founding date · Headquarters location · Company size · Ownership structure · Website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:51:15.322480+00:00