VYPR

Maccms10

by magicblack

Source repositories

CVEs (13)

  • CVE-2021-45786CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

  • CVE-2020-21359CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

  • CVE-2025-28089CriMar 28, 2025
    risk 0.59cvss 9.1epss 0.00

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

  • CVE-2022-35148MedAug 17, 2022
    risk 0.42cvss 6.5epss 0.01

    maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

  • CVE-2020-21363MedAug 11, 2021
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file deletion vulnerability exists within Maccms10.

  • CVE-2022-44870MedJan 6, 2023
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

  • CVE-2022-27887MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.

  • CVE-2022-27886MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.

  • CVE-2020-21387MedOct 4, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.

  • CVE-2020-21362MedAug 11, 2021
    risk 0.35cvss 5.4epss 0.00

    A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.

  • CVE-2025-10395MedSep 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the…

  • CVE-2024-46654MedSep 20, 2024
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-26573MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.