Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sscms MEDIUM 6.5
CVE-2025-52237

An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

Mitigation only
Fix from $1,600 2025-08-05
Siteserver Cms HIGH 7.1
CVE-2025-45529

An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a craf…

No fix yet
Fix from $1,950 2025-05-27
Sscms MEDIUM 5.4
CVE-2023-43953

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

Mitigation only
Fix from $1,600 2023-10-03
Siteserver Cms MEDIUM 6.1
CVE-2023-2862

A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/a…

Fix: after 7.2.1
Fix from $1,600 2023-05-24
Siteserver Cms CRITICAL 9.8
CVE-2022-44298

SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

No fix yet
Fix from $2,300 2023-01-27
Siteserver Cms CRITICAL 9.8
CVE-2022-44297

SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.

No fix yet
Fix from $2,300 2023-01-26
Siteserver Cms MEDIUM 6.1
CVE-2022-30349

siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

No fix yet
Fix from $1,600 2022-06-02
Siteserver Cms CRITICAL 9.8
CVE-2021-42654

SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

Fix: 5.1+
Fix from $2,300 2022-05-24
Siteserver Cms HIGH 8.8
CVE-2021-42655

SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

No fix yet
Fix from $1,950 2022-05-24
Siteserver Cms MEDIUM 5.4
CVE-2021-42656

SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.

Patch available
Fix from $1,600 2022-05-24
Siteserver Cms CRITICAL 9.8
CVE-2022-28118

SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

Fix: after 7.1.2
Fix from $2,300 2022-05-03