Security Advisories
These articles record how Hannon Hill assessed a published vulnerability against Cascade CMS — what the issue is, whether Cascade Cloud and on-premise installations are affected, and any action an administrator needs to take. Most entries conclude that Cascade CMS is not affected; the ones that require action say so at the top of the article.
Reporting a vulnerability
If you believe you've found a security issue in Cascade CMS, contact our support team directly rather than filing it publicly.
Advisories requiring action
Tomcat and Spring
Log4j
CVE-2026-34477
Incomplete TLS hostname verification fix. Not affected by default.
CVE-2026-34480
XmlLayout writes invalid XML. Not affected.
CVE-2021-44228 Log4Shell
The original JNDI lookup RCE. Not affected.
CVE-2021-45046 Log4Shell
Incomplete fix for CVE-2021-44228. Not affected.
CVE-2021-45105 Log4Shell
Self-referential lookup denial of service. Not affected.
CVE-2021-4104
Log4j 1.x JMSAppender RCE. Not affected.
CVE-2022-23302 JMSSink
Log4j 1.x JMSSink deserialization. Not affected.
CVE-2022-23305 JDBCAppender
Log4j 1.x JDBCAppender SQL injection. Not affected.
CVE-2022-23307 Chainsaw Package
Chainsaw deserialization in Log4j 1.2.x. Not affected.