VYPR

Mara CMS

by Mara CMS Project

CVEs (3)

  • CVE-2021-36547CriOct 28, 2021
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

  • CVE-2020-24223MedAug 30, 2020
    risk 0.44cvss 6.1epss 0.15

    Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.

  • CVE-2020-25422MedOct 28, 2021
    risk 0.35cvss 5.4epss 0.01

    A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.