Skip to content
COOEY

FAIL › dossier

taocms

PRODUCT

· dossier confidence 0%

taocms is a CMS product with a documented history of critical security flaws, including remote code execution vulnerabilities in its configuration and file management modules, as well as arbitrary file download flaws in its admin interface.

PROFILE
CategoryCMSWhat they dotaocms is a content management system (CMS) software product.
SECURITY POSTURE

The taocms CMS has a poor security posture, evidenced by multiple critical remote code execution (RCE) vulnerabilities in its core configuration and file management modules, alongside arbitrary file download flaws.

Notable failures
  • CVE-2022-36262: Critical RCE via config.php modification
  • CVE-2022-25578: Critical RCE via .htaccess file editing
  • CVE-2021-44983: Arbitrary file download in file management
Patterns: Critical RCEs in core configuration and web server files; Arbitrary file download in administrative interfaces
FAILURE HISTORY · 2
DATEEVENTSEVSUMMARY
2022-08-15 CVE-2022-36262 critical An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
2022-03-18 CVE-2022-25578 critical taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
Open questions: Is taocms still actively maintained? · What is the current version of taocms?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-08-23 03:49:57.766848+00:00