Skip to content
COOEY

FAIL › dossier

kooboo cms

PRODUCT

· dossier confidence 0%

Kooboo CMS is a content management system with a critical security track record. The vendor failed to patch severe remote code execution vulnerabilities in its file upload functionality, allowing attackers to execute arbitrary code via uploaded files.

PROFILE
CategoryCMSWhat they doKooboo CMS is a content management system.
SECURITY POSTURE

The vendor has a critical track record of unpatched vulnerabilities in its core file upload functionality, allowing remote code execution via arbitrary file extensions.

Notable failures
  • CVE-2021-36581: Insecure file upload allowing arbitrary extensions
  • CVE-2021-36582: Remote shell upload leading to reverse shell
Patterns: repeated unpatched edge-device RCEs; insecure file upload handling
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2021-09-14 CVE-2021-36581 critical Kooboo CMS 2.1.1.0 is vulnerable to Insecure file upload. It is possible to upload any file extension to the server. The server does not verify the extension of the file and the tester was able to upload an aspx to the server.
2021-09-14 CVE-2021-36582 critical In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.
Open questions: Kooboo CMS vendor identity and corporate structure · Post-CVE-2021 patching timeline and remediation efforts
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-21 04:00:53.862311+00:00