SCMS
Products
2- 6 CVEs
- 3 CVEs
Recent CVEs
9| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19925 | Cri | 0.64 | 9.8 | 0.01 | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter. | ||
| CVE-2018-19654 | Hig | 0.49 | 7.5 | 0.01 | Nov 29, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new… | ||
| CVE-2025-45529 | Hig | 0.46 | 7.1 | 0.00 | May 27, 2025 | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor. | ||
| CVE-2025-52237 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2025 | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal. | ||
| CVE-2018-19924 | Med | 0.40 | 6.1 | 0.01 | Dec 6, 2018 | An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address. | ||
| CVE-2023-43953 | Med | 0.35 | 5.4 | 0.00 | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component. | ||
| CVE-2023-43952 | Med | 0.35 | 5.4 | 0.00 | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component. | ||
| CVE-2023-43951 | Med | 0.35 | 5.4 | 0.00 | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component. | ||
| CVE-2009-0330 | 0.03 | — | 0.02 | Jan 29, 2009 | Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter. |
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new…
- risk 0.46cvss 7.1epss 0.00
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
- risk 0.42cvss 6.5epss 0.00
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
- risk 0.40cvss 6.1epss 0.01
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.
- risk 0.35cvss 5.4epss 0.00
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
- risk 0.35cvss 5.4epss 0.00
SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.
- risk 0.35cvss 5.4epss 0.00
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.
- CVE-2009-0330Jan 29, 2009risk 0.03cvss —epss 0.02
Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.