VYPR

Maccms

by Maccms

Source repositories

CVEs (42)

  • CVE-2022-27887MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.

  • CVE-2022-27886MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.

  • CVE-2022-27885MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.

  • CVE-2022-27884MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.

  • CVE-2020-21387MedOct 4, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.

  • CVE-2020-21082MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.

  • CVE-2018-19465MedJun 7, 2019
    risk 0.40cvss 6.1epss 0.01

    Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.

  • CVE-2019-8410MedFeb 27, 2019
    risk 0.40cvss 6.1epss 0.01

    Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key).

  • CVE-2025-45475MedMay 27, 2025
    risk 0.35cvss 5.4epss 0.00

    maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

  • CVE-2022-31303MedJun 21, 2022
    risk 0.35cvss 5.4epss 0.00

    maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

  • CVE-2022-31302MedJun 21, 2022
    risk 0.35cvss 5.4epss 0.00

    maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

  • CVE-2021-45787MedMar 16, 2022
    risk 0.35cvss 5.4epss 0.00

    There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.

  • CVE-2020-21434MedOct 4, 2021
    risk 0.35cvss 5.4epss 0.01

    Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.

  • CVE-2020-21362MedAug 11, 2021
    risk 0.35cvss 5.4epss 0.00

    A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.

  • CVE-2026-7578MedMay 1, 2026
    risk 0.31cvss 4.7epss 0.00

    A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unrestricted upload. The attack may be…

  • CVE-2025-10397MedSep 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and…

  • CVE-2025-10395MedSep 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the…

  • CVE-2025-10122MedSep 9, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made…

  • CVE-2024-46654MedSep 20, 2024
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2026-4563MedMar 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization…