Vulnerability index

Browse CVEs

31 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2025-10397 A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of th… Maccms Mitigation only Fix from $1,9502025-09-14 HIGH 7.2 CVE-2025-10395 A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task… Maccms Mitigation only Fix from $1,9502025-09-14 HIGH 7.2 CVE-2025-10122 A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing … Maccms Mitigation only Fix from $1,9502025-09-09 HIGH 7.3 CVE-2025-45474 maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. Maccms No fix yet Fix from $1,9502025-05-29 MEDIUM 5.4 CVE-2025-45475 maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management. Maccms No fix yet Fix from $1,6002025-05-27 CRITICAL 9.1 CVE-2025-28091 maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. Maccms No fix yet Fix from $2,3002025-03-28 CRITICAL 9.1 CVE-2025-28089 maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. Maccms No fix yet Fix from $2,3002025-03-28 CRITICAL 9.1 CVE-2025-28090 maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. Maccms No fix yet Fix from $2,3002025-03-28 HIGH 7.3 CVE-2024-32391 Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. Maccms No fix yet Fix from $1,9502024-04-19 HIGH 8.8 CVE-2022-47872 A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted p… Maccms No fix yet Fix from $1,9502023-02-01 MEDIUM 6.1 CVE-2022-44870 A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a craf… Maccms No fix yet Fix from $1,6002023-01-06 MEDIUM 5.4 CVE-2022-31302 maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. Maccms No fix yet Fix from $1,6002022-06-21 MEDIUM 5.4 CVE-2022-31303 maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. Maccms No fix yet Fix from $1,6002022-06-21 MEDIUM 6.1 CVE-2021-43707 Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. Maccms No fix yet Fix from $1,6002022-03-31 MEDIUM 6.1 CVE-2022-27884 Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter. Maccms No fix yet Fix from $1,6002022-03-25 MEDIUM 6.1 CVE-2022-27885 Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the sele… Maccms No fix yet Fix from $1,6002022-03-25 MEDIUM 6.1 CVE-2022-27886 Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter. Maccms No fix yet Fix from $1,6002022-03-25 MEDIUM 6.1 CVE-2022-27887 Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter. Maccms No fix yet Fix from $1,6002022-03-25 CRITICAL 9.8 CVE-2021-45786 In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. Maccms No fix yet Fix from $2,3002022-03-16 MEDIUM 5.4 CVE-2020-21434 Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a … Maccms No fix yet Fix from $1,6002021-10-04 HIGH 8.8 CVE-2020-21386 A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges. Maccms No fix yet Fix from $1,9502021-10-04 MEDIUM 6.1 CVE-2020-21387 A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate pri… Maccms No fix yet Fix from $1,6002021-10-04 HIGH 8.1 CVE-2020-20514 A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users. Maccms No fix yet Fix from $1,9502021-09-24 MEDIUM 6.5 CVE-2020-21081 A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted … Maccms No fix yet Fix from $1,6002021-09-14 MEDIUM 6.1 CVE-2020-21082 A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administ… Maccms No fix yet Fix from $1,6002021-09-14 CRITICAL 9.8 CVE-2020-21359 An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execu… Maccms No fix yet Fix from $2,3002021-08-11 MEDIUM 6.5 CVE-2020-21363 An arbitrary file deletion vulnerability exists within Maccms10. Maccms No fix yet Fix from $1,6002021-08-11 MEDIUM 5.4 CVE-2020-21362 A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML vi… Maccms No fix yet Fix from $1,6002021-08-11 HIGH 8.8 CVE-2019-9829 Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs beca… Maccms No fix yet Fix from $1,9502019-03-15 HIGH 8.8 CVE-2018-12114 Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts. Maccms No fix yet Fix from $1,9502018-06-14