Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
maccms vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2019-8410
Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key).
Maccms Maccms
383
VMScore
CVE-2018-19465
Maccms up to and including 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.
Maccms Maccms
312
VMScore
CVE-2021-45787
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
Maccms Maccms 10.0
383
VMScore
CVE-2020-21081
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.
Maccms Maccms 8.0
383
VMScore
CVE-2020-21082
A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows malicious users to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.
Maccms Maccms 8.0
668
VMScore
CVE-2020-21359
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.
Maccms Maccms 10.0
312
VMScore
CVE-2020-21362
A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows malicious users to execute arbitrary web scripts or HTML via the 'wd' parameter.
Maccms Maccms 10.0
312
VMScore
CVE-2020-21434
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
Maccms Maccms 10.0
NA
CVE-2022-35148
maccms10 v2021.1000.1081 to v2022.1000.3031 exists to contain a SQL injection vulnerability via the table parameter at database/columns.html.
Maccms Maccms 10.0
436
VMScore
CVE-2020-20514
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated malicious users to delete all users.
Maccms Maccms 10.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7028
memory leak
log injection
CVE-2024-3400
CVE-2022-48695
CVE-2022-48675
CVE-2024-34487
CVE-2024-33792
spoof
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
NEXT »