VYPR
Vendor

Maccms

Products
1
CVEs
42
Across products
42
Status
Private

Products

1

Recent CVEs

42
View all 42 CVEs →
  • CVE-2017-17733CriDec 18, 2017
    risk 0.67cvss 9.8epss 0.44

    Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

  • CVE-2021-45786CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

  • CVE-2020-21359CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

  • CVE-2018-12114HigJun 14, 2018
    risk 0.60cvss 8.8epss 0.03

    Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

  • CVE-2025-28091CriMar 28, 2025
    risk 0.59cvss 9.1epss 0.00

    maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

  • CVE-2025-28090CriMar 28, 2025
    risk 0.59cvss 9.1epss 0.00

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

  • CVE-2025-28089CriMar 28, 2025
    risk 0.59cvss 9.1epss 0.00

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

  • CVE-2022-47872HigFeb 1, 2023
    risk 0.57cvss 8.8epss 0.01

    A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.

  • CVE-2020-21386HigOct 4, 2021
    risk 0.57cvss 8.8epss 0.00

    A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.

  • CVE-2019-9829HigMar 15, 2019
    risk 0.57cvss 8.8epss 0.02

    Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.

  • CVE-2020-20514HigSep 24, 2021
    risk 0.53cvss 8.1epss 0.00

    A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users.

  • CVE-2024-32391HigApr 19, 2024
    risk 0.48cvss 7.3epss 0.01

    Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

  • CVE-2026-71232HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.00

    MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,…

  • CVE-2026-4562HigMar 23, 2026
    risk 0.47cvss 7.3epss 0.01

    A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The…

  • CVE-2025-45474HigMay 29, 2025
    risk 0.47cvss 7.3epss 0.00

    maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

  • CVE-2022-35148MedAug 17, 2022
    risk 0.42cvss 6.5epss 0.01

    maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

  • CVE-2020-21081MedSep 14, 2021
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

  • CVE-2020-21363MedAug 11, 2021
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file deletion vulnerability exists within Maccms10.

  • CVE-2022-44870MedJan 6, 2023
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

  • CVE-2021-43707MedMar 31, 2022
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.