VYPR
Vendor

magicblack

Products
2
CVEs
15
Across products
16
Status
Private

Products

2

Recent CVEs

15
  • CVE-2021-45786CriMar 16, 2022
    risk 0.64cvss 9.8epss 0.01

    In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

  • CVE-2020-21359CriAug 11, 2021
    risk 0.64cvss 9.8epss 0.02

    An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

  • CVE-2025-28089CriMar 28, 2025
    risk 0.59cvss 9.1epss 0.00

    maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

  • CVE-2022-35148MedAug 17, 2022
    risk 0.42cvss 6.5epss 0.01

    maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

  • CVE-2020-21363MedAug 11, 2021
    risk 0.42cvss 6.5epss 0.01

    An arbitrary file deletion vulnerability exists within Maccms10.

  • CVE-2022-44870MedJan 6, 2023
    risk 0.40cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

  • CVE-2022-27887MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.

  • CVE-2022-27886MedMar 25, 2022
    risk 0.40cvss 6.1epss 0.01

    Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.

  • CVE-2020-21387MedOct 4, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.

  • CVE-2020-21082MedSep 14, 2021
    risk 0.40cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.

  • CVE-2020-21362MedAug 11, 2021
    risk 0.35cvss 5.4epss 0.00

    A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.

  • CVE-2025-10397MedSep 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and…

  • CVE-2025-10395MedSep 14, 2025
    risk 0.31cvss 4.7epss 0.00

    A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the…

  • CVE-2024-46654MedSep 20, 2024
    risk 0.31cvss 4.8epss 0.00

    A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

  • CVE-2022-26573MedMar 25, 2022
    risk 0.00cvss 6.1epss 0.01

    Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.