FAIL › dossier
kooboo
VENDOR· dossier confidence 20%
Kooboo CMS is an open-source ASP.NET-based content management system with a critical security track record. The vendor failed to patch severe remote code execution vulnerabilities in its file upload functionality, allowing attackers to execute arbitrary code via uploaded files.
PROFILE
CategoryCMSWhat they doKooboo CMS is an open-source content management system built on the ASP.NET platform.Founded2011
SECURITY POSTURE
The vendor has a critical track record of unpatched vulnerabilities in its core file upload functionality, allowing remote code execution via arbitrary file extensions.
Notable failures
- CVE-2021-36581: Insecure file upload allowing arbitrary file extension upload
- CVE-2021-36582: Remote shell upload enabling reverse shell execution
Patterns: repeated unpatched edge-device RCEs; insecure file upload leading to arbitrary code execution
Reputationsevere-fallout (-0.26) · 14 trusted sources
CoverageCISA · NVD · SentinelOne · chromereleases.googleblog.com · cooey · cooey
FAILURE HISTORY · 2
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-09-14 | CVE-2021-36581 | critical | Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server. |
| 2021-09-14 | CVE-2021-36582 | critical | In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.80
Widely condemned for enabling remote shell upload in CMS
synthesissevere-fallout-0.80
Widely condemned due to critical file upload vulnerability allowing ASPX execution
Neutral database listing
Neutral vulnerability database listing
Irrelevant unrelated news
Irrelevant unrelated news
Irrelevant unrelated advisory page
Irrelevant unrelated release notes
Negative
Damning
"Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server."
Neutral
Negative
Neutral
Neutral
Negative
Damning disclosure of remote shell upload capability
"In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server."
DOSSIER SOURCES
Open questions: Kooboo CMS founding date · Kooboo CMS headquarters location · Kooboo CMS company size · Kooboo CMS ownership structure · Kooboo CMS official website URL
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-22 04:12:21.430540+00:00