Sscms
Products
2- 10 CVEs
- 6 CVEs
Recent CVEs
16| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-44298 | Cri | 0.64 | 9.8 | 0.01 | Jan 27, 2023 | SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | ||
| CVE-2022-44297 | Cri | 0.64 | 9.8 | 0.01 | Jan 26, 2023 | SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | ||
| CVE-2021-42654 | Cri | 0.64 | 9.8 | 0.02 | May 24, 2022 | SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | ||
| CVE-2022-28118 | Cri | 0.64 | 9.8 | 0.03 | May 3, 2022 | SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | ||
| CVE-2021-42655 | Hig | 0.57 | 8.8 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | ||
| CVE-2026-7435 | Hig | 0.47 | 7.2 | 0.00 | Apr 30, 2026 | SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic… | ||
| CVE-2025-45529 | Hig | 0.46 | 7.1 | 0.00 | May 27, 2025 | An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor. | ||
| CVE-2025-52237 | Med | 0.42 | 6.5 | 0.00 | Aug 5, 2025 | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal. | ||
| CVE-2026-4234 | Med | 0.41 | 6.3 | 0.00 | Mar 16, 2026 | A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component DDL Handler. The manipulation of the argument tableHandWrite results in sql injection. The attack can be executed remotely. The… | ||
| CVE-2022-30349 | Med | 0.40 | 6.1 | 0.01 | Jun 2, 2022 | siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | ||
| CVE-2026-4542 | Med | 0.35 | 5.4 | 0.00 | Mar 22, 2026 | A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from… | ||
| CVE-2023-43953 | Med | 0.35 | 5.4 | 0.00 | Oct 3, 2023 | SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component. | ||
| CVE-2021-42656 | Med | 0.35 | 5.4 | 0.01 | May 24, 2022 | SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | ||
| CVE-2022-44299 | Med | 0.32 | 4.9 | 0.01 | Feb 16, 2023 | SiteServerCMS 7.1.3 sscms has a file read vulnerability. | ||
| CVE-2026-4222 | Low | 0.25 | 3.8 | 0.00 | Mar 16, 2026 | A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is… | ||
| CVE-2023-2862 | Low | 0.23 | 3.5 | 0.01 | May 24, 2023 | A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack… |
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
- risk 0.64cvss 9.8epss 0.02
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.03
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
- risk 0.57cvss 8.8epss 0.01
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
- risk 0.47cvss 7.2epss 0.00
SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic…
- risk 0.46cvss 7.1epss 0.00
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
- risk 0.42cvss 6.5epss 0.00
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
- risk 0.41cvss 6.3epss 0.00
A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component DDL Handler. The manipulation of the argument tableHandWrite results in sql injection. The attack can be executed remotely. The…
- risk 0.40cvss 6.1epss 0.01
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
- risk 0.35cvss 5.4epss 0.00
A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from…
- risk 0.35cvss 5.4epss 0.00
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
- risk 0.35cvss 5.4epss 0.01
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
- risk 0.32cvss 4.9epss 0.01
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
- risk 0.25cvss 3.8epss 0.00
A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is…
- risk 0.23cvss 3.5epss 0.01
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack…