Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
chshcms vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2023-5029
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the publi...
Chshcms Mccms 2.6
8.8
CVSSv3
CVE-2023-3235
A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched re...
Chshcms Mccms
8.8
CVSSv3
CVE-2023-3236
A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remote...
Chshcms Mccms
9.8
CVSSv3
CVE-2023-26781
SQL injection vulnerability in mccms 2.6 allows remote malicious users to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
Chshcms Mccms 2.6
6.5
CVSSv3
CVE-2023-26782
An issue discovered in mccms 2.6.1 allows remote malicious users to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
Chshcms Mccms 2.6.1
8.8
CVSSv3
CVE-2023-29815
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
Chshcms Mccms 2.6.3
6.5
CVSSv3
CVE-2022-30898
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote malicious users to change the administrator's username and password.
Chshcms Cscms 4.2
9.8
CVSSv3
CVE-2022-29660
CSCMS Music Portal System v4.2 exists to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.
Chshcms Cscms Music Portal System 4.2
7.2
CVSSv3
CVE-2022-29661
CSCMS Music Portal System v4.2 exists to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.
Chshcms Cscms Music Portal System 4.2
7.2
CVSSv3
CVE-2022-29662
CSCMS Music Portal System v4.2 exists to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.
Chshcms Cscms Music Portal System 4.2
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »