VYPR
Vendor

SCMS

Products
2
CVEs
9
Across products
9
Status
Private

Products

2

Recent CVEs

9
  • CVE-2018-19925CriDec 6, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. It has SQL injection via the member/member_order.php type parameter, related to the O_state parameter.

  • CVE-2018-19654HigNov 29, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new…

  • CVE-2025-45529HigMay 27, 2025
    risk 0.46cvss 7.1epss 0.00

    An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

  • CVE-2025-52237MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

  • CVE-2018-19924MedDec 6, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. An email address can be modified in between the request for a validation code and the entry of the validation code, leading to storage of an XSS payload contained in the modified address.

  • CVE-2023-43953MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

  • CVE-2023-43952MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component.

  • CVE-2023-43951MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Column Management component.

  • CVE-2009-0330Jan 29, 2009
    risk 0.03cvss epss 0.02

    Directory traversal vulnerability in index.php in Simple Content Management System (SCMS) 1 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the p parameter.