Перейти к содержимому
Noroxi

Записи maccms

37 опубликованных записей вендора maccms.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

37 записей
  • CVE-2017-17733
    52В плане

    Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

    КритическаяCVSS 9,8Эксплойта нетEPSS 44 %

    maccms · maccms18 дек. 2017 г.

  • CVE-2020-21359
    40В плане

    An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    maccms · maccms11 авг. 2021 г.

  • CVE-2021-45786
    39Наблюдать

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    maccms · maccms16 мар. 2022 г.

  • CVE-2018-12114
    36Наблюдать

    Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

    ВысокаяCVSS 8,8Proof of conceptEPSS 3 %

    maccms · maccms14 июн. 2018 г.

  • CVE-2019-9829
    36Наблюдать

    Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    maccms · maccms14 мар. 2019 г.

  • CVE-2025-28089
    36Наблюдать

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    maccms · maccms28 мар. 2025 г.

  • CVE-2025-28091
    36Наблюдать

    maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    maccms · maccms28 мар. 2025 г.

  • CVE-2025-28090
    36Наблюдать

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    maccms · maccms28 мар. 2025 г.

  • CVE-2022-47872
    35Наблюдать

    A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a

    ВысокаяCVSS 8,8Proof of conceptEPSS 1 %

    maccms · maccms1 февр. 2023 г.

  • CVE-2020-21386
    35Наблюдать

    A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator priv

    ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %

    maccms · maccms4 окт. 2021 г.

  • CVE-2020-20514
    32Наблюдать

    A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all u

    ВысокаяCVSS 8,1Эксплойта нетEPSS 0 %

    maccms · maccms24 сент. 2021 г.

  • CVE-2024-32391
    29Наблюдать

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

    ВысокаяCVSS 7,3Эксплойта нетEPSS 1 %

    maccms · maccms19 апр. 2024 г.

  • CVE-2025-45474
    29Наблюдать

    maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

    ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %

    maccms · maccms29 мая 2025 г.

  • CVE-2020-21363
    26Наблюдать

    An arbitrary file deletion vulnerability exists within Maccms10.

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    maccms · maccms11 авг. 2021 г.

  • CVE-2022-35148
    26Наблюдать

    maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/colu

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    maccms · maccms17 авг. 2022 г.

  • CVE-2020-21081
    26Наблюдать

    A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    maccms · maccms14 сент. 2021 г.

  • CVE-2019-8410
    24Наблюдать

    Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords paramet

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms27 февр. 2019 г.

  • CVE-2018-19465
    24Наблюдать

    Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms7 июн. 2019 г.

  • CVE-2020-21082
    24Наблюдать

    A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms14 сент. 2021 г.

  • CVE-2021-43707
    24Наблюдать

    Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms31 мар. 2022 г.

  • CVE-2020-21387
    24Наблюдать

    A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and esc

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms4 окт. 2021 г.

  • CVE-2022-26573
    24Наблюдать

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms25 мар. 2022 г.

  • CVE-2022-27884
    24Наблюдать

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd par

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms25 мар. 2022 г.

  • CVE-2022-27885
    24Наблюдать

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms25 мар. 2022 г.

  • CVE-2022-27886
    24Наблюдать

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd par

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    maccms · maccms25 мар. 2022 г.