Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
maccms vulnerabilities and exploits
(subscribe to this query)
6.1
CVSSv3
CVE-2022-27886
Maccms v10 exists to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
Maccms Maccms 10.0
5.4
CVSSv3
CVE-2022-31302
maccms8 exists to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
Maccms Maccms 8.0
8.8
CVSSv3
CVE-2018-12114
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
Maccms Maccms 10.0
1 EDB exploit
8.8
CVSSv3
CVE-2022-47872
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows malicious users to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.
Maccms Maccms 10.0
1 Github repository
5.4
CVSSv3
CVE-2022-31303
maccms10 exists to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
Maccms Maccms 10.0
6.5
CVSSv3
CVE-2022-35148
maccms10 v2021.1000.1081 to v2022.1000.3031 exists to contain a SQL injection vulnerability via the table parameter at database/columns.html.
Maccms Maccms 10.0
8.1
CVSSv3
CVE-2020-20514
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated malicious users to delete all users.
Maccms Maccms 10.0
9.8
CVSSv3
CVE-2017-17733
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.
Maccms Maccms 8.0
9.8
CVSSv3
CVE-2021-45786
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
Maccms Maccms 10.0
6.1
CVSSv3
CVE-2021-43707
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
Maccms Maccms 10.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-33572
CVE-2024-24919
CVE-2024-0230
CVE-2024-32714
HTML injection
local file inclusion
CVE-2024-31098
CVE-2024-31244
privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »