VYPR

Magnolia CMS

by Magnolia

CVEs (10)

  • CVE-2021-46362CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.05

    A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.

  • CVE-2021-46361CriFeb 11, 2022
    risk 0.64cvss 9.8epss 0.03

    An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload.

  • CVE-2021-46366HigFeb 11, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

  • CVE-2021-46365HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

  • CVE-2021-46364HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

  • CVE-2021-46363HigFeb 11, 2022
    risk 0.51cvss 7.8epss 0.02

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary code execution on a victim's computer when opening the exported files with Microsoft Excel.

  • CVE-2022-33098MedJul 7, 2022
    risk 0.47cvss 6.1epss 0.52

    Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.

  • CVE-2021-25894MedApr 2, 2021
    risk 0.40cvss 6.1epss 0.01

    Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter.

  • CVE-2021-25893MedApr 2, 2021
    risk 0.35cvss 5.4epss 0.01

    Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/.

  • CVE-2026-18478MedAug 10, 2026
    risk 0.33cvss epss

    Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10