Siteserver
Products
3- 30 CVEs
- 5 CVEs
- 2 CVEs
Recent CVEs
34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44298 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2023 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | ||
| CVE-2022-44297 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2023 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | ||
| CVE-2021-42654 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | ||
| CVE-2022-28118 | Cri | 0.64 | 9.8 | 0.03 | May 3, 2022 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | ||
| CVE-2007-1966 | Cri | 0.59 | 9.1 | 0.01 | Apr 11, 2007 | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | ||
| CVE-2021-42655 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | ||
| CVE-2026-7435 | Hig | 0.47 | 7.2 | 0.01 | Apr 30, 2026 | SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic… | ||
| CVE-2022-36226 | Hig | 0.47 | 7.2 | 0.01 | Aug 26, 2022 | SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx. | ||
| CVE-2022-30349 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2022 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2019-11401 | Hig | 0.40 | 7.2 | 0.03 | Apr 22, 2019 | A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted. | ||
| CVE-2015-8376 | Med | 0.40 | 6.1 | 0.01 | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1. | ||
| CVE-2021-42656 | Med | 0.35 | 5.4 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | ||
| CVE-2026-82486 | Med | 0.33 | 5.0 | 0.00 | Aug 30, 2026 | A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is… | ||
| CVE-2022-44299 | Med | 0.32 | 4.9 | 0.01 | Feb 16, 2023 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. | ||
| CVE-2026-7429 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2026 | SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can… | ||
| CVE-2023-2862 | Low | 0.23 | 3.5 | 0.01 | May 24, 2023 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack… | ||
| CVE-2006-4963 | 0.04 | — | 0.07 | Sep 23, 2006 | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code… | |||
| CVE-2006-4559 | 0.04 | — | 0.07 | Sep 6, 2006 | Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3)… | |||
| CVE-2013-4952 | 0.03 | — | 0.01 | Jul 29, 2013 | SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2012-5293 | 0.03 | — | 0.03 | Oct 4, 2012 | Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to… |
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
- risk 0.64cvss 9.8epss 0.02
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
- risk 0.59cvss 9.1epss 0.01
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
- risk 0.57cvss 8.8epss 0.01
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
- risk 0.47cvss 7.2epss 0.01
SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic…
- risk 0.47cvss 7.2epss 0.01
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
- risk 0.40cvss 6.1epss 0.01
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
- risk 0.40cvss 7.2epss 0.03
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.
- risk 0.35cvss 5.4epss 0.01
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
- risk 0.33cvss 5.0epss 0.00
A vulnerability was found in SiteServer SSCMS 7.4.0. Affected by this issue is some unknown functionality of the component Agent Installation Workflow. Performing a manipulation of the argument SecurityKey results in improper access controls. Remote exploitation of the attack is…
- risk 0.32cvss 4.9epss 0.01
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
- risk 0.30cvss 4.6epss 0.00
SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can…
- risk 0.23cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack…
- CVE-2006-4963Sep 23, 2006risk 0.04cvss —epss 0.07
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code…
- CVE-2006-4559Sep 6, 2006risk 0.04cvss —epss 0.07
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3)…
- CVE-2013-4952Jul 29, 2013risk 0.03cvss —epss 0.01
SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2012-5293Oct 4, 2012risk 0.03cvss —epss 0.03
Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to…