Siteserver CMS
by Sscms
CVEs (10)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44298 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2023 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | ||
| CVE-2022-44297 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2023 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | ||
| CVE-2021-42654 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | ||
| CVE-2022-28118 | Cri | 0.64 | 9.8 | 0.03 | May 3, 2022 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | ||
| CVE-2021-42655 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | ||
| CVE-2025-45529 | Hig | 0.46 | 7.1 | 0.00 | May 27, 2025 | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor. | ||
| CVE-2022-30349 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2022 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2021-42656 | Med | 0.35 | 5.4 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | ||
| CVE-2022-44299 | Med | 0.32 | 4.9 | 0.01 | Feb 16, 2023 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. | ||
| CVE-2023-2862 | Low | 0.23 | 3.5 | 0.01 | May 24, 2023 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack… |
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
- risk 0.64cvss 9.8epss 0.02
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
- risk 0.57cvss 8.8epss 0.01
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
- risk 0.46cvss 7.1epss 0.00
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
- risk 0.40cvss 6.1epss 0.01
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
- risk 0.35cvss 5.4epss 0.01
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
- risk 0.32cvss 4.9epss 0.01
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
- risk 0.23cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack…