Siteserver
Products
4- 29 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
30| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44298 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2023 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | ||
| CVE-2022-44297 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2023 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | ||
| CVE-2021-42654 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | ||
| CVE-2007-1966 | Cri | 0.59 | 9.1 | 0.01 | Apr 11, 2007 | Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | ||
| CVE-2021-42655 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | ||
| CVE-2026-7435 | Hig | 0.47 | 7.2 | 0.00 | Apr 30, 2026 | SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic… | ||
| CVE-2022-36226 | Hig | 0.47 | 7.2 | 0.01 | Aug 26, 2022 | SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx. | ||
| CVE-2019-11401 | Hig | 0.40 | 7.2 | 0.03 | Apr 22, 2019 | A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted. | ||
| CVE-2015-8376 | Med | 0.40 | 6.1 | 0.01 | Jan 8, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1. | ||
| CVE-2022-44299 | Med | 0.32 | 4.9 | 0.01 | Feb 16, 2023 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. | ||
| CVE-2026-7429 | Med | 0.30 | 4.6 | 0.00 | Apr 30, 2026 | SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can… | ||
| CVE-2023-2862 | Low | 0.23 | 3.5 | 0.01 | May 24, 2023 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack… | ||
| CVE-2006-4963 | 0.04 | — | 0.07 | Sep 23, 2006 | Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code… | |||
| CVE-2013-4952 | 0.03 | — | 0.01 | Jul 29, 2013 | SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |||
| CVE-2012-5293 | 0.03 | — | 0.03 | Oct 4, 2012 | Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to… | |||
| CVE-2010-2674 | 0.03 | — | 0.01 | Jul 8, 2010 | SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action. | |||
| CVE-2010-2358 | 0.03 | — | 0.03 | Jun 21, 2010 | PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path] parameter. NOTE: some of… | |||
| CVE-2009-4876 | 0.03 | — | 0.02 | May 26, 2010 | admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter. | |||
| CVE-2010-2047 | 0.03 | — | 0.01 | May 25, 2010 | SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. NOTE: some of these details are obtained from third party information. | |||
| CVE-2009-4723 | 0.03 | — | 0.02 | Mar 18, 2010 | Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter. |
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
- risk 0.64cvss 9.8epss 0.02
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
- risk 0.59cvss 9.1epss 0.01
Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie.
- risk 0.57cvss 8.8epss 0.01
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
- risk 0.47cvss 7.2epss 0.00
SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic…
- risk 0.47cvss 7.2epss 0.01
SiteServerCMS 5.X has a Remote-download-Getshell-vulnerability via /SiteServer/Ajax/ajaxOtherService.aspx.
- risk 0.40cvss 7.2epss 0.03
A issue was discovered in SiteServer CMS 6.9.0. It allows remote attackers to execute arbitrary code because an administrator can add the permitted file extension .aassp, which is converted to .asp because the "as" substring is deleted.
- risk 0.40cvss 6.1epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Symphony CMS 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) Navigation Group, or (3) Label parameter to blueprints/sections/edit/1.
- risk 0.32cvss 4.9epss 0.01
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
- risk 0.30cvss 4.6epss 0.00
SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attackers to execute arbitrary JavaScript by crafting malicious STL template payloads that are decrypted and returned without proper sanitization. Attackers can…
- risk 0.23cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack…
- CVE-2006-4963Sep 23, 2006risk 0.04cvss —epss 0.07
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code…
- CVE-2013-4952Jul 29, 2013risk 0.03cvss —epss 0.01
SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
- CVE-2012-5293Oct 4, 2012risk 0.03cvss —epss 0.03
Multiple PHP remote file inclusion vulnerabilities in SAPID CMS 1.2.3 Stable allow remote attackers to execute arbitrary PHP code via a URL in the (1) GLOBALS[root_path] parameter to usr/extensions/get_tree.inc.php or (2) root_path parameter to…
- CVE-2010-2674Jul 8, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in TSOKA:CMS 1.1, 1.9, and 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in an articolo action.
- CVE-2010-2358Jun 21, 2010risk 0.03cvss —epss 0.03
PHP remote file inclusion vulnerability in modules/catalog/upload_photo.php in Nakid CMS 0.5.2, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the core[system_path] parameter. NOTE: some of…
- CVE-2009-4876May 26, 2010risk 0.03cvss —epss 0.02
admin/cikkform.php in Netrix CMS 1.0 allows remote attackers to modify arbitrary pages via a direct request using the cid parameter.
- CVE-2010-2047May 25, 2010risk 0.03cvss —epss 0.01
SQL injection vulnerability in index.php in JE CMS 1.0.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the categoryid parameter in a viewcategory action. NOTE: some of these details are obtained from third party information.
- CVE-2009-4723Mar 18, 2010risk 0.03cvss —epss 0.02
Directory traversal vulnerability in confirm.php in Netpet CMS 1.9 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter.