VYPR
Vendor

Melisplatform

Products
5
CVEs
6
Across products
6
Status
Private

Products

5

Recent CVEs

6
  • CVE-2025-10353CriOct 8, 2025
    risk 0.54cvss epss 0.03

    File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform. This vulnerability allows an attacker to upload a malicious file via a POST request to '/melis/MelisCmsSlider/MelisCmsSliderDetails/saveDetailsForm'…

  • CVE-2025-10352CriOct 8, 2025
    risk 0.53cvss epss 0.00

    Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthenticated attacker to create an administrator account via a request to '/melis/MelisCore/ToolUser/addNewUser'.

  • CVE-2025-10351CriOct 8, 2025
    risk 0.53cvss epss 0.00

    SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates'…

  • CVE-2022-39298Oct 12, 2022
    risk 0.00cvss epss 0.01

    MelisFront is the engine that displays website hosted on Melis Platform. It deals with showing pages, plugins, URL rewritting, search optimization and SEO, etc. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-front`, and ultimately leads to…

  • CVE-2022-39297Oct 12, 2022
    risk 0.00cvss epss 0.01

    MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools. Attackers can deserialize arbitrary data on affected versions of `melisplatform/melis-cms`, and ultimately leads to the execution of arbitrary…

  • CVE-2022-39296Oct 11, 2022
    risk 0.00cvss epss 0.01

    MelisAssetManager provides deliveries of Melis Platform's assets located in every module's public folder. Attackers can read arbitrary files on affected versions of `melisplatform/melis-asset-manager`, leading to the disclosure of sensitive information. Conducting this attack…