Записи sscms
12 опубликованных записей вендора sscms.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-27 Path Traversal: 'dir/../../filename'1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-552 Files or Directories Accessible to External Parties1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2022-28118Proof of concept | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.sscms · siteserver cms | Критическая9,8 | — | 2,8 % | 2 мая 2022 г. |
40В плане | CVE-2021-42654Эксплойта нет | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrasscms · siteserver cms · CWE-434 | Критическая9,8 | — | 1,7 % | 24 мая 2022 г. |
39Наблюдать | CVE-2022-44297Эксплойта нет | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.sscms · siteserver cms · CWE-89 | Критическая9,8 | — | 1,0 % | 26 янв. 2023 г. |
39Наблюдать | CVE-2022-44298Эксплойта нет | SiteServer CMS 7.1.3 is vulnerable to SQL Injection.sscms · siteserver cms · CWE-89 | Критическая9,8 | — | 0,7 % | 27 янв. 2023 г. |
35Наблюдать | CVE-2021-42655Эксплойта нет | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.sscms · siteserver cms · CWE-89 | Высокая8,8 | — | 1,2 % | 24 мая 2022 г. |
28Наблюдать | CVE-2025-45529Эксплойта нет | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sendisscms · siteserver cms · CWE-552 | Высокая7,1 | — | 0,3 % | 27 мая 2025 г. |
26Наблюдать | CVE-2025-52237Эксплойта нет | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.sscms · sscms · CWE-27 | Средняя6,5 | — | 0,5 % | 5 авг. 2025 г. |
24Наблюдать | CVE-2022-30349Эксплойта нет | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).sscms · siteserver cms · CWE-79 | Средняя6,1 | — | 0,7 % | 2 июн. 2022 г. |
24Наблюдать | CVE-2023-2862Эксплойта нет | SiteServer CMS search cross site scriptingsscms · siteserver cms · CWE-79 | Средняя6,1 | — | 0,6 % | 24 мая 2023 г. |
21Наблюдать | CVE-2021-42656Эксплойта нет | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.sscms · siteserver cms · CWE-79 | Средняя5,4 | — | 0,7 % | 24 мая 2022 г. |
21Наблюдать | CVE-2023-43953Эксплойта нет | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.sscms · sscms · CWE-79 | Средняя5,4 | — | 0,3 % | 3 окт. 2023 г. |
19Наблюдать | CVE-2022-44299Эксплойта нет | SiteServerCMS 7.1.3 sscms has a file read vulnerability.sscms · siteserver cms · CWE-22 | Средняя4,9 | — | 0,8 % | 16 февр. 2023 г. |
- CVE-2022-2811840В плане
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
КритическаяCVSS 9,8Proof of conceptEPSS 3 %sscms · siteserver cms2 мая 2022 г.
- CVE-2021-4265440В плане
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitra
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sscms · siteserver cms24 мая 2022 г.
- CVE-2022-4429739Наблюдать
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sscms · siteserver cms26 янв. 2023 г.
- CVE-2022-4429839Наблюдать
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %sscms · siteserver cms27 янв. 2023 г.
- CVE-2021-4265535Наблюдать
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sscms · siteserver cms24 мая 2022 г.
- CVE-2025-4552928Наблюдать
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sendi
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %sscms · siteserver cms27 мая 2025 г.
- CVE-2025-5223726Наблюдать
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
СредняяCVSS 6,5Эксплойта нетEPSS 0 %sscms · sscms5 авг. 2025 г.
- CVE-2022-3034924Наблюдать
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sscms · siteserver cms2 июн. 2022 г.
- CVE-2023-286224Наблюдать
SiteServer CMS search cross site scripting
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sscms · siteserver cms24 мая 2023 г.
- CVE-2021-4265621Наблюдать
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %sscms · siteserver cms24 мая 2022 г.
- CVE-2023-4395321Наблюдать
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %sscms · sscms3 окт. 2023 г.
- CVE-2022-4429919Наблюдать
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
СредняяCVSS 4,9Эксплойта нетEPSS 1 %sscms · siteserver cms16 февр. 2023 г.