Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mura Cms CRITICAL 9.8
CVE-2025-67830

Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.

Fix: 10.1.4+
Fix from $2,300 2026-03-18
Mura Cms CRITICAL 9.8
CVE-2025-67829

Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.

Fix: 10.1.4+
Fix from $2,300 2026-03-18
Mura Cms HIGH 8.8
CVE-2025-55040

The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 8.8
CVE-2025-55044

The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations …

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 8.1
CVE-2025-55046

MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system thr…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 8.0
CVE-2025-55041

MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allow…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms HIGH 7.1
CVE-2025-55045

The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable…

Mitigation only
Fix from $1,950 2026-03-18
Mura Cms MEDIUM 6.5
CVE-2025-55043

MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenti…

Mitigation only
Fix from $1,600 2026-03-18
Mura Cms CRITICAL 9.8
CVE-2022-47003

A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

Fix: 10.0.580+
Fix from $2,300 2023-02-01