sscms records
12 published records for vendor sscms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-27 Path Traversal: 'dir/../../filename'1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-552 Files or Directories Accessible to External Parties1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-28118Proof of concept | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.sscms · siteserver cms | Critical9.8 | — | 2.8% | May 2, 2022 |
40Plan | CVE-2021-42654No exploit | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrasscms · siteserver cms · CWE-434 | Critical9.8 | — | 1.7% | May 24, 2022 |
39Monitor | CVE-2022-44297No exploit | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.sscms · siteserver cms · CWE-89 | Critical9.8 | — | 1.0% | Jan 26, 2023 |
39Monitor | CVE-2022-44298No exploit | SiteServer CMS 7.1.3 is vulnerable to SQL Injection.sscms · siteserver cms · CWE-89 | Critical9.8 | — | 0.7% | Jan 27, 2023 |
35Monitor | CVE-2021-42655No exploit | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.sscms · siteserver cms · CWE-89 | High8.8 | — | 1.2% | May 24, 2022 |
28Monitor | CVE-2025-45529No exploit | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sendisscms · siteserver cms · CWE-552 | High7.1 | — | 0.3% | May 27, 2025 |
26Monitor | CVE-2025-52237No exploit | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.sscms · sscms · CWE-27 | Medium6.5 | — | 0.5% | Aug 5, 2025 |
24Monitor | CVE-2022-30349No exploit | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).sscms · siteserver cms · CWE-79 | Medium6.1 | — | 0.7% | Jun 2, 2022 |
24Monitor | CVE-2023-2862No exploit | SiteServer CMS search cross site scriptingsscms · siteserver cms · CWE-79 | Medium6.1 | — | 0.6% | May 24, 2023 |
21Monitor | CVE-2021-42656No exploit | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.sscms · siteserver cms · CWE-79 | Medium5.4 | — | 0.7% | May 24, 2022 |
21Monitor | CVE-2023-43953No exploit | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.sscms · sscms · CWE-79 | Medium5.4 | — | 0.3% | Oct 3, 2023 |
19Monitor | CVE-2022-44299No exploit | SiteServerCMS 7.1.3 sscms has a file read vulnerability.sscms · siteserver cms · CWE-22 | Medium4.9 | — | 0.8% | Feb 16, 2023 |
- CVE-2022-2811840Plan
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
CriticalCVSS 9.8Proof of conceptEPSS 3%sscms · siteserver cmsMay 2, 2022
- CVE-2021-4265440Plan
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitra
CriticalCVSS 9.8No exploitEPSS 2%sscms · siteserver cmsMay 24, 2022
- CVE-2022-4429739Monitor
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
CriticalCVSS 9.8No exploitEPSS 1%sscms · siteserver cmsJan 26, 2023
- CVE-2022-4429839Monitor
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
CriticalCVSS 9.8No exploitEPSS 1%sscms · siteserver cmsJan 27, 2023
- CVE-2021-4265535Monitor
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
HighCVSS 8.8No exploitEPSS 1%sscms · siteserver cmsMay 24, 2022
- CVE-2025-4552928Monitor
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sendi
HighCVSS 7.1No exploitEPSS 0%sscms · siteserver cmsMay 27, 2025
- CVE-2025-5223726Monitor
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
MediumCVSS 6.5No exploitEPSS 0%sscms · sscmsAug 5, 2025
- CVE-2022-3034924Monitor
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
MediumCVSS 6.1No exploitEPSS 1%sscms · siteserver cmsJun 2, 2022
- CVE-2023-286224Monitor
SiteServer CMS search cross site scripting
MediumCVSS 6.1No exploitEPSS 1%sscms · siteserver cmsMay 24, 2023
- CVE-2021-4265621Monitor
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
MediumCVSS 5.4No exploitEPSS 1%sscms · siteserver cmsMay 24, 2022
- CVE-2023-4395321Monitor
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
MediumCVSS 5.4No exploitEPSS 0%sscms · sscmsOct 3, 2023
- CVE-2022-4429919Monitor
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
MediumCVSS 4.9No exploitEPSS 1%sscms · siteserver cmsFeb 16, 2023