Vendor CVEs
Maccms
All CVEs
43 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17733 | Cri | 0.67 | 9.8 | 0.44 | Dec 18, 2017 | Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request. | ||
| CVE-2021-45786 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2022 | In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. | ||
| CVE-2020-21359 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2021 | An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name. | ||
| CVE-2018-12114 | Hig | 0.60 | 8.8 | 0.03 | Jun 14, 2018 | Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. | ||
| CVE-2025-28091 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. | ||
| CVE-2025-28090 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. | ||
| CVE-2025-28089 | Cri | 0.59 | 9.1 | 0.00 | Mar 28, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. | ||
| CVE-2022-47872 | Hig | 0.57 | 8.8 | 0.01 | Feb 1, 2023 | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module. | ||
| CVE-2020-21386 | Hig | 0.57 | 8.8 | 0.00 | Oct 4, 2021 | A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges. | ||
| CVE-2019-9829 | Hig | 0.57 | 8.8 | 0.02 | Mar 15, 2019 | Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates. | ||
| CVE-2020-20514 | Hig | 0.53 | 8.1 | 0.00 | Sep 24, 2021 | A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users. | ||
| CVE-2024-32391 | Hig | 0.48 | 7.3 | 0.01 | Apr 19, 2024 | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. | ||
| CVE-2026-71232 | Hig | 0.47 | 7.2 | 0.01 | Aug 5, 2026 | MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,… | ||
| CVE-2026-4562 | Hig | 0.47 | 7.3 | 0.01 | Mar 23, 2026 | A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The… | ||
| CVE-2025-45474 | Hig | 0.47 | 7.3 | 0.00 | May 29, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. | ||
| CVE-2026-75465 | Hig | 0.42 | 7.5 | 0.01 | Aug 25, 2026 | The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafted HTTP GET request with limit and… | ||
| CVE-2022-35148 | Med | 0.42 | 6.5 | 0.01 | Aug 17, 2022 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. | ||
| CVE-2020-21081 | Med | 0.42 | 6.5 | 0.00 | Sep 14, 2021 | A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL. | ||
| CVE-2020-21363 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2021 | An arbitrary file deletion vulnerability exists within Maccms10. | ||
| CVE-2022-44870 | Med | 0.40 | 6.1 | 0.01 | Jan 6, 2023 | A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module. | ||
| CVE-2021-43707 | Med | 0.40 | 6.1 | 0.01 | Mar 31, 2022 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. | ||
| CVE-2022-27887 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2022 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter. | ||
| CVE-2022-27886 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2022 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter. | ||
| CVE-2022-27885 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2022 | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters. | ||
| CVE-2022-27884 | Med | 0.40 | 6.1 | 0.01 | Mar 25, 2022 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter. | ||
| CVE-2020-21387 | Med | 0.40 | 6.1 | 0.01 | Oct 4, 2021 | A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload. | ||
| CVE-2020-21082 | Med | 0.40 | 6.1 | 0.01 | Sep 14, 2021 | A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names. | ||
| CVE-2018-19465 | Med | 0.40 | 6.1 | 0.01 | Jun 7, 2019 | Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html. | ||
| CVE-2019-8410 | Med | 0.40 | 6.1 | 0.01 | Feb 27, 2019 | Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key). | ||
| CVE-2025-45475 | Med | 0.35 | 5.4 | 0.00 | May 27, 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management. | ||
| CVE-2022-31303 | Med | 0.35 | 5.4 | 0.00 | Jun 21, 2022 | maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | ||
| CVE-2022-31302 | Med | 0.35 | 5.4 | 0.00 | Jun 21, 2022 | maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | ||
| CVE-2021-45787 | Med | 0.35 | 5.4 | 0.00 | Mar 16, 2022 | There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks. | ||
| CVE-2020-21434 | Med | 0.35 | 5.4 | 0.01 | Oct 4, 2021 | Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field. | ||
| CVE-2020-21362 | Med | 0.35 | 5.4 | 0.00 | Aug 11, 2021 | A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter. | ||
| CVE-2026-7578 | Med | 0.31 | 4.7 | 0.00 | May 1, 2026 | A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unrestricted upload. The attack may be… | ||
| CVE-2025-10397 | Med | 0.31 | 4.7 | 0.00 | Sep 14, 2025 | A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and… | ||
| CVE-2025-10395 | Med | 0.31 | 4.7 | 0.00 | Sep 14, 2025 | A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the… | ||
| CVE-2025-10122 | Med | 0.31 | 4.7 | 0.00 | Sep 9, 2025 | A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made… | ||
| CVE-2024-46654 | Med | 0.31 | 4.8 | 0.00 | Sep 20, 2024 | A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | ||
| CVE-2026-4563 | Med | 0.28 | 4.3 | 0.00 | Mar 23, 2026 | A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization… | ||
| CVE-2026-15516 | Med | 0.00 | 5.6 | 0.00 | Jul 13, 2026 | A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The… | ||
| CVE-2022-26573 | Med | 0.00 | 6.1 | 0.01 | Mar 25, 2022 | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters. |
- risk 0.67cvss 9.8epss 0.44
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.
- risk 0.64cvss 9.8epss 0.01
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
- risk 0.64cvss 9.8epss 0.02
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.
- risk 0.60cvss 8.8epss 0.03
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
- risk 0.59cvss 9.1epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
- risk 0.57cvss 8.8epss 0.01
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
- risk 0.57cvss 8.8epss 0.00
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.
- risk 0.57cvss 8.8epss 0.02
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.
- risk 0.53cvss 8.1epss 0.00
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/.html allows authenticated attackers to delete all users.
- risk 0.48cvss 7.3epss 0.01
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
- risk 0.47cvss 7.2epss 0.01
MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex, but the blacklist omitted exec, passthru, popen, show_source, create_function, register_shutdown_function,…
- risk 0.47cvss 7.3epss 0.01
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The…
- risk 0.47cvss 7.3epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
- risk 0.42cvss 7.5epss 0.01
The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote attacker can send a crafted HTTP GET request with limit and…
- risk 0.42cvss 6.5epss 0.01
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
- risk 0.42cvss 6.5epss 0.00
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
- risk 0.42cvss 6.5epss 0.01
An arbitrary file deletion vulnerability exists within Maccms10.
- risk 0.40cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.
- risk 0.40cvss 6.1epss 0.01
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
- risk 0.40cvss 6.1epss 0.01
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.
- risk 0.40cvss 6.1epss 0.01
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
- risk 0.40cvss 6.1epss 0.01
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.
- risk 0.40cvss 6.1epss 0.01
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.
- risk 0.40cvss 6.1epss 0.01
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.
- risk 0.40cvss 6.1epss 0.01
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.
- risk 0.40cvss 6.1epss 0.01
Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key).
- risk 0.35cvss 5.4epss 0.00
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
- risk 0.35cvss 5.4epss 0.00
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
- risk 0.35cvss 5.4epss 0.00
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
- risk 0.35cvss 5.4epss 0.00
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
- risk 0.35cvss 5.4epss 0.01
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
- risk 0.35cvss 5.4epss 0.00
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.
- risk 0.31cvss 4.7epss 0.00
A weakness has been identified in MacCMS Pro up to 2022.1.3. This vulnerability affects the function install of the file /admi.php/admin/addon/add.html of the component Plugin Installation Handler. Executing a manipulation can lead to unrestricted upload. The attack may be…
- risk 0.31cvss 4.7epss 0.00
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and…
- risk 0.31cvss 4.7epss 0.00
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the…
- risk 0.31cvss 4.7epss 0.00
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made…
- risk 0.31cvss 4.8epss 0.00
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
- risk 0.28cvss 4.3epss 0.00
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization…
- risk 0.00cvss 5.6epss 0.00
A vulnerability was detected in MacCMS Pro up to 2022.1000.3005. Impacted is the function step5 of the file application/install/controller/Index.php of the component Installation Module. The manipulation results in authorization bypass. The attack may be launched remotely. The…
- risk 0.00cvss 6.1epss 0.01
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.