Vulnerability index

Browse CVEs

51 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2025-51818 MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands Mccms No fix yet Fix from $1,6002025-08-21 MEDIUM 6.5 CVE-2025-50234 MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processe… Mccms No fix yet Fix from $1,6002025-08-06 MEDIUM 5.5 CVE-2025-51651 An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary fil… Mccms No fix yet Fix from $1,6002025-07-14 HIGH 8.8 CVE-2025-5327 A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/… Mccms No fix yet Fix from $1,9502025-05-29 HIGH 8.8 CVE-2025-5328 A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sy… Mccms No fix yet Fix from $1,9502025-05-29 HIGH 8.8 CVE-2023-5029 A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46… Mccms No fix yet Fix from $1,9502023-09-17 CRITICAL 9.8 CVE-2023-26781 SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. Mccms No fix yet Fix from $2,3002023-04-28 MEDIUM 6.5 CVE-2023-26782 An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cach… Mccms No fix yet Fix from $1,6002023-04-28 HIGH 8.8 CVE-2023-29815 mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). Mccms No fix yet Fix from $1,9502023-04-28 MEDIUM 6.5 CVE-2022-30898 A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username an… Cscms No fix yet Fix from $1,6002022-06-09 HIGH 7.2 CVE-2022-29687 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29688 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/h… Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29689 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/d… Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 CRITICAL 9.8 CVE-2022-29660EPSS 12% CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. Cscms Music Portal System No fix yet Fix from $2,3002022-05-26 HIGH 8.8 CVE-2022-29664 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 8.8 CVE-2022-29667 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploit… Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 8.8 CVE-2022-29669 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 8.8 CVE-2022-29685 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29661 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29662 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29663 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29665 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29666 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29670 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29676 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29680 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29681 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29682 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29683 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26 HIGH 7.2 CVE-2022-29684 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del. Cscms Music Portal System No fix yet Fix from $1,9502022-05-26