murasoftware records
9 published records for vendor murasoftware.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-47003Proof of concept | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web requestmurasoftware · mura cms · CWE-287 | Critical9.8 | — | 3.6% | Feb 1, 2023 |
39Monitor | CVE-2025-67830No exploit | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.murasoftware · mura cms · CWE-89 | Critical9.8 | — | 0.3% | Mar 18, 2026 |
39Monitor | CVE-2025-67829No exploit | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.murasoftware · mura cms · CWE-89 | Critical9.8 | — | 0.3% | Mar 18, 2026 |
35Monitor | CVE-2025-55040No exploit | The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSmurasoftware · mura cms · CWE-352 | High8.8 | — | 0.2% | Mar 18, 2026 |
35Monitor | CVE-2025-55044No exploit | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized lmurasoftware · mura cms · CWE-352 | High8.8 | — | 0.1% | Mar 18, 2026 |
32Monitor | CVE-2025-55041No exploit | MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) tmurasoftware · mura cms · CWE-352 | High8.0 | — | 0.1% | Mar 18, 2026 |
32Monitor | CVE-2025-55046No exploit | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash smurasoftware · mura cms · CWE-352 | High8.1 | — | 0.1% | Mar 18, 2026 |
28Monitor | CVE-2025-55045No exploit | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF.murasoftware · mura cms · CWE-352 | High7.1 | — | 0.1% | Mar 18, 2026 |
26Monitor | CVE-2025-55043No exploit | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows umurasoftware · mura cms · CWE-352 | Medium6.5 | — | 0.2% | Mar 18, 2026 |
- CVE-2022-4700340Plan
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request
CriticalCVSS 9.8Proof of conceptEPSS 4%murasoftware · mura cmsFeb 1, 2023
- CVE-2025-6783039Monitor
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
CriticalCVSS 9.8No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-6782939Monitor
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
CriticalCVSS 9.8No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-5504035Monitor
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CS
HighCVSS 8.8No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-5504435Monitor
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized l
HighCVSS 8.8No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-5504132Monitor
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) t
HighCVSS 8.0No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-5504632Monitor
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash s
HighCVSS 8.1No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-5504528Monitor
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF.
HighCVSS 7.1No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026
- CVE-2025-5504326Monitor
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows u
MediumCVSS 6.5No exploitEPSS 0%murasoftware · mura cmsMar 18, 2026