maccms kayıtları
maccms üreticisine ait 37 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')18
- CWE-918 Server-Side Request Forgery (SSRF)8
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-287 Improper Authentication1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
37 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
52Planlayın | CVE-2017-17733İstismar yok | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.maccms · maccms | Kritik9,8 | — | %44,1 | 18 Ara 2017 |
40Planlayın | CVE-2020-21359İstismar yok | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verificationmaccms · maccms · CWE-434 | Kritik9,8 | — | %1,7 | 11 Ağu 2021 |
39İzleyin | CVE-2021-45786İstismar yok | In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.maccms · maccms · CWE-287 | Kritik9,8 | — | %1,2 | 16 Mar 2022 |
36İzleyin | CVE-2018-12114Kavram kanıtı | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.maccms · maccms · CWE-352 | Yüksek8,8 | — | %2,9 | 14 Haz 2018 |
36İzleyin | CVE-2019-9829İstismar yok | Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action.maccms · maccms · CWE-829 | Yüksek8,8 | — | %2,0 | 14 Mar 2019 |
36İzleyin | CVE-2025-28089İstismar yok | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.maccms · maccms · CWE-918 | Kritik9,1 | — | %0,4 | 28 Mar 2025 |
36İzleyin | CVE-2025-28091İstismar yok | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.maccms · maccms · CWE-918 | Kritik9,1 | — | %0,4 | 28 Mar 2025 |
36İzleyin | CVE-2025-28090İstismar yok | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.maccms · maccms · CWE-918 | Kritik9,1 | — | %0,4 | 28 Mar 2025 |
35İzleyin | CVE-2022-47872Kavram kanıtı | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a maccms · maccms · CWE-918 | Yüksek8,8 | — | %0,9 | 1 Şub 2023 |
35İzleyin | CVE-2020-21386İstismar yok | A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privmaccms · maccms · CWE-352 | Yüksek8,8 | — | %0,4 | 4 Eki 2021 |
32İzleyin | CVE-2020-20514İstismar yok | A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all umaccms · maccms · CWE-352 | Yüksek8,1 | — | %0,4 | 24 Eyl 2021 |
29İzleyin | CVE-2024-32391İstismar yok | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.maccms · maccms · CWE-79 | Yüksek7,3 | — | %0,9 | 19 Nis 2024 |
29İzleyin | CVE-2025-45474İstismar yok | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.maccms · maccms · CWE-918 | Yüksek7,3 | — | %0,4 | 29 May 2025 |
26İzleyin | CVE-2020-21363İstismar yok | An arbitrary file deletion vulnerability exists within Maccms10.maccms · maccms · CWE-610 | Orta6,5 | — | %0,8 | 11 Ağu 2021 |
26İzleyin | CVE-2022-35148İstismar yok | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columaccms · maccms · CWE-89 | Orta6,5 | — | %0,7 | 17 Ağu 2022 |
26İzleyin | CVE-2020-21081İstismar yok | A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on amaccms · maccms · CWE-352 | Orta6,5 | — | %0,4 | 14 Eyl 2021 |
24İzleyin | CVE-2019-8410İstismar yok | Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parametmaccms · maccms · CWE-79 | Orta6,1 | — | %0,9 | 27 Şub 2019 |
24İzleyin | CVE-2018-19465İstismar yok | Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_maccms · maccms · CWE-79 | Orta6,1 | — | %0,8 | 7 Haz 2019 |
24İzleyin | CVE-2020-21082İstismar yok | A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to stealmaccms · maccms · CWE-79 | Orta6,1 | — | %0,7 | 14 Eyl 2021 |
24İzleyin | CVE-2021-43707İstismar yok | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.maccms · maccms · CWE-79 | Orta6,1 | — | %0,6 | 31 Mar 2022 |
24İzleyin | CVE-2020-21387İstismar yok | A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escmaccms · maccms · CWE-79 | Orta6,1 | — | %0,6 | 4 Eki 2021 |
24İzleyin | CVE-2022-26573İstismar yok | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via themaccms · maccms · CWE-79 | Orta6,1 | — | %0,6 | 25 Mar 2022 |
24İzleyin | CVE-2022-27884İstismar yok | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parmaccms · maccms · CWE-79 | Orta6,1 | — | %0,6 | 25 Mar 2022 |
24İzleyin | CVE-2022-27885İstismar yok | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html viamaccms · maccms · CWE-79 | Orta6,1 | — | %0,6 | 25 Mar 2022 |
24İzleyin | CVE-2022-27886İstismar yok | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parmaccms · maccms · CWE-79 | Orta6,1 | — | %0,6 | 25 Mar 2022 |
- CVE-2017-1773352Planlayın
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.
KritikCVSS 9,8İstismar yokEPSS %44maccms · maccms18 Ara 2017
- CVE-2020-2135940Planlayın
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification
KritikCVSS 9,8İstismar yokEPSS %2maccms · maccms11 Ağu 2021
- CVE-2021-4578639İzleyin
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
KritikCVSS 9,8İstismar yokEPSS %1maccms · maccms16 Mar 2022
- CVE-2018-1211436İzleyin
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
YüksekCVSS 8,8Kavram kanıtıEPSS %3maccms · maccms14 Haz 2018
- CVE-2019-982936İzleyin
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action.
YüksekCVSS 8,8İstismar yokEPSS %2maccms · maccms14 Mar 2019
- CVE-2025-2808936İzleyin
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
KritikCVSS 9,1İstismar yokEPSS %0maccms · maccms28 Mar 2025
- CVE-2025-2809136İzleyin
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
KritikCVSS 9,1İstismar yokEPSS %0maccms · maccms28 Mar 2025
- CVE-2025-2809036İzleyin
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
KritikCVSS 9,1İstismar yokEPSS %0maccms · maccms28 Mar 2025
- CVE-2022-4787235İzleyin
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a
YüksekCVSS 8,8Kavram kanıtıEPSS %1maccms · maccms1 Şub 2023
- CVE-2020-2138635İzleyin
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator priv
YüksekCVSS 8,8İstismar yokEPSS %0maccms · maccms4 Eki 2021
- CVE-2020-2051432İzleyin
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all u
YüksekCVSS 8,1İstismar yokEPSS %0maccms · maccms24 Eyl 2021
- CVE-2024-3239129İzleyin
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
YüksekCVSS 7,3İstismar yokEPSS %1maccms · maccms19 Nis 2024
- CVE-2025-4547429İzleyin
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
YüksekCVSS 7,3İstismar yokEPSS %0maccms · maccms29 May 2025
- CVE-2020-2136326İzleyin
An arbitrary file deletion vulnerability exists within Maccms10.
OrtaCVSS 6,5İstismar yokEPSS %1maccms · maccms11 Ağu 2021
- CVE-2022-3514826İzleyin
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/colu
OrtaCVSS 6,5İstismar yokEPSS %1maccms · maccms17 Ağu 2022
- CVE-2020-2108126İzleyin
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a
OrtaCVSS 6,5İstismar yokEPSS %0maccms · maccms14 Eyl 2021
- CVE-2019-841024İzleyin
Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords paramet
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms27 Şub 2019
- CVE-2018-1946524İzleyin
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms7 Haz 2019
- CVE-2020-2108224İzleyin
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms14 Eyl 2021
- CVE-2021-4370724İzleyin
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms31 Mar 2022
- CVE-2020-2138724İzleyin
A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and esc
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms4 Eki 2021
- CVE-2022-2657324İzleyin
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms25 Mar 2022
- CVE-2022-2788424İzleyin
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd par
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms25 Mar 2022
- CVE-2022-2788524İzleyin
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms25 Mar 2022
- CVE-2022-2788624İzleyin
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd par
OrtaCVSS 6,1İstismar yokEPSS %1maccms · maccms25 Mar 2022