Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mkcms project vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2020-22818
MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter.
Mkcms Project Mkcms 6.2
9.8
CVSSv3
CVE-2020-22820
MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter.
Mkcms Project Mkcms 6.2
8.8
CVSSv3
CVE-2019-11332
MKCMS 5.0 allows remote malicious users to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the password, as demonstrated by 123456.
Mkcms Project Mkcms 5.0
9.8
CVSSv3
CVE-2019-10707
MKCMS V5.0 has SQL injection via the bplay.php play parameter.
Mkcms Project Mkcms 5.0
9.8
CVSSv3
CVE-2020-22819
MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter.
Mkcms Project Mkcms 6.2
8.8
CVSSv3
CVE-2019-11078
MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.
Mkcms Project Mkcms 5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-29895
blind SQL injection
CVE-2024-5064
CVE-2023-52677
CVE-2023-52682
CVE-2024-30051
CVE-2024-35849
remote attackers
remote
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started