murasoftware kayıtları
murasoftware üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2022-47003Kavram kanıtı | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web requestmurasoftware · mura cms · CWE-287 | Kritik9,8 | — | %3,6 | 1 Şub 2023 |
39İzleyin | CVE-2025-67830İstismar yok | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.murasoftware · mura cms · CWE-89 | Kritik9,8 | — | %0,3 | 18 Mar 2026 |
39İzleyin | CVE-2025-67829İstismar yok | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.murasoftware · mura cms · CWE-89 | Kritik9,8 | — | %0,3 | 18 Mar 2026 |
35İzleyin | CVE-2025-55040İstismar yok | The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSmurasoftware · mura cms · CWE-352 | Yüksek8,8 | — | %0,2 | 18 Mar 2026 |
35İzleyin | CVE-2025-55044İstismar yok | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized lmurasoftware · mura cms · CWE-352 | Yüksek8,8 | — | %0,1 | 18 Mar 2026 |
32İzleyin | CVE-2025-55041İstismar yok | MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) tmurasoftware · mura cms · CWE-352 | Yüksek8,0 | — | %0,1 | 18 Mar 2026 |
32İzleyin | CVE-2025-55046İstismar yok | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash smurasoftware · mura cms · CWE-352 | Yüksek8,1 | — | %0,1 | 18 Mar 2026 |
28İzleyin | CVE-2025-55045İstismar yok | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF.murasoftware · mura cms · CWE-352 | Yüksek7,1 | — | %0,1 | 18 Mar 2026 |
26İzleyin | CVE-2025-55043İstismar yok | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows umurasoftware · mura cms · CWE-352 | Orta6,5 | — | %0,2 | 18 Mar 2026 |
- CVE-2022-4700340Planlayın
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request
KritikCVSS 9,8Kavram kanıtıEPSS %4murasoftware · mura cms1 Şub 2023
- CVE-2025-6783039İzleyin
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
KritikCVSS 9,8İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-6782939İzleyin
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
KritikCVSS 9,8İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-5504035İzleyin
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CS
YüksekCVSS 8,8İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-5504435İzleyin
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized l
YüksekCVSS 8,8İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-5504132İzleyin
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) t
YüksekCVSS 8,0İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-5504632İzleyin
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash s
YüksekCVSS 8,1İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-5504528İzleyin
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF.
YüksekCVSS 7,1İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026
- CVE-2025-5504326İzleyin
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows u
OrtaCVSS 6,5İstismar yokEPSS %0murasoftware · mura cms18 Mar 2026