Vulnerability index

Browse CVEs

36 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Maccms HIGH 7.2
CVE-2025-10397

A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of th…

Mitigation only
Fix from $1,950 2025-09-14
Maccms HIGH 7.2
CVE-2025-10395

A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task…

Mitigation only
Fix from $1,950 2025-09-14
Maccms HIGH 7.2
CVE-2025-10122

A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing …

Mitigation only
Fix from $1,950 2025-09-09
Maccms HIGH 7.3
CVE-2025-45474

maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

No fix yet
Fix from $1,950 2025-05-29
Maccms MEDIUM 5.4
CVE-2025-45475

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

No fix yet
Fix from $1,600 2025-05-27
Maccms CRITICAL 9.1
CVE-2025-28091

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

No fix yet
Fix from $2,300 2025-03-28
Maccms CRITICAL 9.1
CVE-2025-28089

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

No fix yet
Fix from $2,300 2025-03-28
Maccms CRITICAL 9.1
CVE-2025-28090

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

No fix yet
Fix from $2,300 2025-03-28
Maccms HIGH 7.3
CVE-2024-32391

Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

No fix yet
Fix from $1,950 2024-04-19
Maccms HIGH 8.8
CVE-2022-47872

A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted p…

No fix yet
Fix from $1,950 2023-02-01
Maccms MEDIUM 6.1
CVE-2022-44870

A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a craf…

No fix yet
Fix from $1,600 2023-01-06
Maccms MEDIUM 6.5
CVE-2022-35148

maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

Patch available
Fix from $1,600 2022-08-17
Maccms MEDIUM 5.4
CVE-2022-31302

maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

No fix yet
Fix from $1,600 2022-06-21
Maccms MEDIUM 5.4
CVE-2022-31303

maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

No fix yet
Fix from $1,600 2022-06-21
Maccms MEDIUM 6.1
CVE-2021-43707

Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

No fix yet
Fix from $1,600 2022-03-31
Maccms MEDIUM 6.1
CVE-2022-27884

Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.

No fix yet
Fix from $1,600 2022-03-25
Maccms MEDIUM 6.1
CVE-2022-27885

Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the sele…

No fix yet
Fix from $1,600 2022-03-25
Maccms MEDIUM 6.1
CVE-2022-27886

Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.

No fix yet
Fix from $1,600 2022-03-25
Maccms MEDIUM 6.1
CVE-2022-27887

Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.

No fix yet
Fix from $1,600 2022-03-25
Maccms MEDIUM 6.1
CVE-2022-26573

Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select a…

Patch available
Fix from $1,600 2022-03-25
Maccms CRITICAL 9.8
CVE-2021-45786

In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

No fix yet
Fix from $2,300 2022-03-16
Maccms MEDIUM 5.4
CVE-2021-45787

There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions inclu…

Patch available
Fix from $1,600 2022-03-16
Maccms MEDIUM 5.4
CVE-2020-21434

Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a …

No fix yet
Fix from $1,600 2021-10-04
Maccms HIGH 8.8
CVE-2020-21386

A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.

No fix yet
Fix from $1,950 2021-10-04
Maccms MEDIUM 6.1
CVE-2020-21387

A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate pri…

No fix yet
Fix from $1,600 2021-10-04
Maccms HIGH 8.1
CVE-2020-20514

A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.

No fix yet
Fix from $1,950 2021-09-24
Maccms MEDIUM 6.5
CVE-2020-21081

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted …

No fix yet
Fix from $1,600 2021-09-14
Maccms MEDIUM 6.1
CVE-2020-21082

A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administ…

No fix yet
Fix from $1,600 2021-09-14
Maccms CRITICAL 9.8
CVE-2020-21359

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execu…

No fix yet
Fix from $2,300 2021-08-11
Maccms MEDIUM 6.5
CVE-2020-21363

An arbitrary file deletion vulnerability exists within Maccms10.

No fix yet
Fix from $1,600 2021-08-11