VYPR
Vendor

Sscms

Products
2
CVEs
16
Across products
16
Status
Private

Products

2

Recent CVEs

16
  • CVE-2022-44298CriJan 27, 2023
    risk 0.64cvss 9.8epss 0.01

    SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

  • CVE-2022-44297CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.01

    SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.

  • CVE-2021-42654CriMay 24, 2022
    risk 0.64cvss 9.8epss 0.02

    SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

  • CVE-2022-28118CriMay 3, 2022
    risk 0.64cvss 9.8epss 0.03

    SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

  • CVE-2021-42655HigMay 24, 2022
    risk 0.57cvss 8.8epss 0.01

    SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

  • CVE-2026-7435HigApr 30, 2026
    risk 0.47cvss 7.2epss 0.00

    SSCMS v7.4.0 contains a SQL injection vulnerability in the stl:sqlContent tag where the queryString attribute is passed directly to database execution without parameterization or sanitization. Attackers can craft encrypted payloads submitted to the /api/stl/actions/dynamic…

  • CVE-2025-45529HigMay 27, 2025
    risk 0.46cvss 7.1epss 0.00

    An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

  • CVE-2025-52237MedAug 5, 2025
    risk 0.42cvss 6.5epss 0.00

    An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

  • CVE-2026-4234MedMar 16, 2026
    risk 0.41cvss 6.3epss 0.00

    A security flaw has been discovered in SSCMS 7.4.0. This vulnerability affects unknown code of the file SitesAddController.Submit.cs of the component DDL Handler. The manipulation of the argument tableHandWrite results in sql injection. The attack can be executed remotely. The…

  • CVE-2022-30349MedJun 2, 2022
    risk 0.40cvss 6.1epss 0.01

    siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

  • CVE-2026-4542MedMar 22, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability has been found in SSCMS 4.7.0. The affected element is an unknown function of the file LayerImageController.Submit.cs of the component layerImage Endpoint. Such manipulation of the argument filePaths leads to path traversal. The attack may be performed from…

  • CVE-2023-43953MedOct 3, 2023
    risk 0.35cvss 5.4epss 0.00

    SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

  • CVE-2021-42656MedMay 24, 2022
    risk 0.35cvss 5.4epss 0.01

    SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.

  • CVE-2022-44299MedFeb 16, 2023
    risk 0.32cvss 4.9epss 0.01

    SiteServerCMS 7.1.3 sscms has a file read vulnerability.

  • CVE-2026-4222LowMar 16, 2026
    risk 0.25cvss 3.8epss 0.00

    A vulnerability was determined in SSCMS up to 7.4.0. This vulnerability affects the function PathUtils.RemoveParentPath of the file /api/admin/plugins/install/actions/download. This manipulation of the argument path causes path traversal. Remote exploitation of the attack is…

  • CVE-2023-2862LowMay 24, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack…