Maccms
Products
1- 42 CVEs
Recent CVEs
42| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17733 | Cri | 0.67 | 9.8 | 0.44 | Dec 18, 2017 | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. | ||
| CVE-2021-45786 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. | ||
| CVE-2020-21359 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2021 | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name. | ||
| CVE-2018-12114 | Hig | 0.60 | 8.8 | 0.03 | Jun 14, 2018 | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. | ||
| CVE-2025-28091 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. | ||
| CVE-2025-28090 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. | ||
| CVE-2025-28089 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. | ||
| CVE-2022-47872 | Hig | 0.57 | 8.8 | 0.01 | Feb 1, 2023 | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module. | ||
| CVE-2020-21386 | Hig | 0.57 | 8.8 | 0.00 | Oct 4, 2021 | A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges. | ||
| CVE-2019-9829 | Hig | 0.57 | 8.8 | 0.02 | Mar 15, 2019 | Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates. | ||
| CVE-2020-20514 | Hig | 0.53 | 8.1 | 0.00 | Sep 24, 2021 | A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users. | ||
| CVE-2024-32391 | Hig | 0.48 | 7.3 | 0.01 | Apr 19, 2024 | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. | ||
| CVE-2026-71232 | Hig | 0.47 | 7.2 | 0.00 | Aug 5, 2026 | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,… | ||
| CVE-2026-4562 | Hig | 0.47 | 7.3 | 0.01 | Mar 23, 2026 | A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The… | ||
| CVE-2025-45474 | Hig | 0.47 | 7.3 | 0.00 | May 29, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. | ||
| CVE-2022-35148 | Med | 0.42 | 6.5 | 0.01 | Aug 17, 2022 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. | ||
| CVE-2020-21081 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2021 | A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL. | ||
| CVE-2020-21363 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2021 | An arbitrary file deletion vulnerability exists within Maccms10. | ||
| CVE-2022-44870 | Med | 0.40 | 6.1 | 0.01 | Jan 6, 2023 | A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module. | ||
| CVE-2021-43707 | Med | 0.40 | 6.1 | 0.01 | Mar 31, 2022 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. |
- risk 0.67cvss 9.8epss 0.44
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.
- risk 0.64cvss 9.8epss 0.01
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.
- risk 0.60cvss 8.8epss 0.03
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
- risk 0.57cvss 8.8epss 0.01
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.
- risk 0.57cvss 8.8epss 0.02
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.
- risk 0.53cvss 8.1epss 0.00
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users.
- risk 0.48cvss 7.3epss 0.01
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
- risk 0.47cvss 7.2epss 0.00
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,…
- risk 0.47cvss 7.3epss 0.01
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The…
- risk 0.47cvss 7.3epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
- risk 0.42cvss 6.5epss 0.01
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
- risk 0.42cvss 6.5epss 0.00
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
- risk 0.42cvss 6.5epss 0.01
An arbitrary file deletion vulnerability exists within Maccms10.
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.