maccms
Web & CMS Pluginsoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting maccms.
- CVE-2025-10397Magicblack MacCMS API server-side request forgery4.7
- CVE-2025-10395Magicblack MacCMS Scheduled Task col_url server-side request forgery4.7
- CVE-2025-10122Maccms10 Database.php rep sql injection4.7
- CVE-2025-45474maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.7.3
- CVE-2025-45475maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.5.4
- CVE-2025-28091maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.9.1
- CVE-2025-28090maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.9.1
- CVE-2025-28089maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.9.1
- CVE-2024-46654A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.4.8
- CVE-2024-32391Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.7.3
- CVE-2022-47872A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under th...8.8
- CVE-2022-44870A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter und...6.1
- CVE-2022-35148maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.6.5
- CVE-2022-31303maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.5.4
- CVE-2022-31302maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.5.4