Vulnerability index

Browse CVEs

53 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mccms MEDIUM 5.4
CVE-2025-51818

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

No fix yet
Fix from $1,600 2025-08-21
Mccms MEDIUM 6.5
CVE-2025-50234

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processe…

No fix yet
Fix from $1,600 2025-08-06
Mccms MEDIUM 5.5
CVE-2025-51651

An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary fil…

No fix yet
Fix from $1,600 2025-07-14
Mccms HIGH 8.8
CVE-2025-5327

A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/…

No fix yet
Fix from $1,950 2025-05-29
Mccms HIGH 8.8
CVE-2025-5328

A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sy…

No fix yet
Fix from $1,950 2025-05-29
Mccms HIGH 8.8
CVE-2023-5029

A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46…

No fix yet
Fix from $1,950 2023-09-17
Mccms HIGH 8.8
CVE-2023-3235

A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/co…

Fix: after 2.6.5
Fix from $1,950 2023-06-14
Mccms HIGH 8.8
CVE-2023-3236

A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin…

Fix: after 2.6.5
Fix from $1,950 2023-06-14
Mccms CRITICAL 9.8
CVE-2023-26781

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

No fix yet
Fix from $2,300 2023-04-28
Mccms MEDIUM 6.5
CVE-2023-26782

An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cach…

No fix yet
Fix from $1,600 2023-04-28
Mccms HIGH 8.8
CVE-2023-29815

mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).

No fix yet
Fix from $1,950 2023-04-28
Cscms MEDIUM 6.5
CVE-2022-30898

A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username an…

No fix yet
Fix from $1,600 2022-06-09
Cscms Music Portal System HIGH 7.2
CVE-2022-29687

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29688

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/h…

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29689

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/d…

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System CRITICAL 9.8
CVE-2022-29660EPSS 12%

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

No fix yet
Fix from $2,300 2022-05-26
Cscms Music Portal System HIGH 8.8
CVE-2022-29664

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 8.8
CVE-2022-29667

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploit…

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 8.8
CVE-2022-29669

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 8.8
CVE-2022-29685

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29661

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29662

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29663

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29665

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29666

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29670

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29676

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29680

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29681

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.

No fix yet
Fix from $1,950 2022-05-26
Cscms Music Portal System HIGH 7.2
CVE-2022-29682

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.

No fix yet
Fix from $1,950 2022-05-26