Skip to content
COOEY

FAIL › dossier

espcms

PRODUCT

· dossier confidence 60%

ESPCMS is a CMS product with a critical security track record, including three remote code execution vulnerabilities discovered in November 2022.

PROFILE
CategorySoftware ProductWhat they doESPCMS is a Content Management System (CMS) product.
SECURITY POSTURE

Critical security vulnerabilities (RCE) were discovered in November 2022, indicating a failure to patch or secure core components against remote exploitation.

Notable failures
  • CVE-2022-44088: Remote Code Execution in INPUT_ISDESCRIPTION
  • CVE-2022-44089: Remote Code Execution in IS_GETCACHE
  • CVE-2022-44087: Remote Code Execution in UPFILE_PIC_ZOOM_HIGHT
Patterns: Multiple critical RCE vulnerabilities discovered in same release; Vulnerabilities in core input and file handling components
FAILURE HISTORY · 3
DATEEVENTSEVSUMMARY
2022-11-10 CVE-2022-44088 critical ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
2022-11-10 CVE-2022-44089 critical ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
2022-11-10 CVE-2022-44087 critical ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
Open questions: ESPCMS is a product, not a company; no independent corporate profile data available · No founding date, headquarters, or size data available for ESPCMS or its parent company
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-13 17:52:11.657128+00:00