VYPR

SCMS

by SCMS

CVEs (6)

  • CVE-2025-45529HigMay 27, 2025
    risk 0.46cvss 7.1epss 0.00

    An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

  • CVE-2025-52237MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

  • CVE-2023-43953MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

  • CVE-2023-43952MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.

  • CVE-2023-43951MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.

  • CVE-2009-0330Jan 29, 2009
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.