İçeriğe atla
Noroxi

maccms kayıtları

maccms üreticisine ait 37 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
3
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

37 kayıt
  • CVE-2017-17733
    52Planlayın

    Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

    KritikCVSS 9,8İstismar yokEPSS %44

    maccms · maccms18 Ara 2017

  • CVE-2020-21359
    40Planlayın

    An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification

    KritikCVSS 9,8İstismar yokEPSS %2

    maccms · maccms11 Ağu 2021

  • CVE-2021-45786
    39İzleyin

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

    KritikCVSS 9,8İstismar yokEPSS %1

    maccms · maccms16 Mar 2022

  • CVE-2018-12114
    36İzleyin

    Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

    YüksekCVSS 8,8Kavram kanıtıEPSS %3

    maccms · maccms14 Haz 2018

  • CVE-2019-9829
    36İzleyin

    Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action.

    YüksekCVSS 8,8İstismar yokEPSS %2

    maccms · maccms14 Mar 2019

  • CVE-2025-28089
    36İzleyin

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

    KritikCVSS 9,1İstismar yokEPSS %0

    maccms · maccms28 Mar 2025

  • CVE-2025-28091
    36İzleyin

    maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

    KritikCVSS 9,1İstismar yokEPSS %0

    maccms · maccms28 Mar 2025

  • CVE-2025-28090
    36İzleyin

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

    KritikCVSS 9,1İstismar yokEPSS %0

    maccms · maccms28 Mar 2025

  • CVE-2022-47872
    35İzleyin

    A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    maccms · maccms1 Şub 2023

  • CVE-2020-21386
    35İzleyin

    A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator priv

    YüksekCVSS 8,8İstismar yokEPSS %0

    maccms · maccms4 Eki 2021

  • CVE-2020-20514
    32İzleyin

    A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all u

    YüksekCVSS 8,1İstismar yokEPSS %0

    maccms · maccms24 Eyl 2021

  • CVE-2024-32391
    29İzleyin

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

    YüksekCVSS 7,3İstismar yokEPSS %1

    maccms · maccms19 Nis 2024

  • CVE-2025-45474
    29İzleyin

    maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

    YüksekCVSS 7,3İstismar yokEPSS %0

    maccms · maccms29 May 2025

  • CVE-2020-21363
    26İzleyin

    An arbitrary file deletion vulnerability exists within Maccms10.

    OrtaCVSS 6,5İstismar yokEPSS %1

    maccms · maccms11 Ağu 2021

  • CVE-2022-35148
    26İzleyin

    maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/colu

    OrtaCVSS 6,5İstismar yokEPSS %1

    maccms · maccms17 Ağu 2022

  • CVE-2020-21081
    26İzleyin

    A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a

    OrtaCVSS 6,5İstismar yokEPSS %0

    maccms · maccms14 Eyl 2021

  • CVE-2019-8410
    24İzleyin

    Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords paramet

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms27 Şub 2019

  • CVE-2018-19465
    24İzleyin

    Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms7 Haz 2019

  • CVE-2020-21082
    24İzleyin

    A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms14 Eyl 2021

  • CVE-2021-43707
    24İzleyin

    Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms31 Mar 2022

  • CVE-2020-21387
    24İzleyin

    A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and esc

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms4 Eki 2021

  • CVE-2022-26573
    24İzleyin

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms25 Mar 2022

  • CVE-2022-27884
    24İzleyin

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd par

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms25 Mar 2022

  • CVE-2022-27885
    24İzleyin

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms25 Mar 2022

  • CVE-2022-27886
    24İzleyin

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd par

    OrtaCVSS 6,1İstismar yokEPSS %1

    maccms · maccms25 Mar 2022