CVE-2026-40309
- EPSS 0.17%
- Veröffentlicht 06.05.2026 20:16:32
- Zuletzt bearbeitet 06.05.2026 21:22:50
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cTrash.empty function does not validate anti-CSRF tokens for trash management requests. An attacker can induce a logged-in administrator to submit a forg...
CVE-2026-40325
- EPSS 0.15%
- Veröffentlicht 06.05.2026 20:16:32
- Zuletzt bearbeitet 06.05.2026 21:22:50
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the `cTrash.restore` function does not properly validate anti-CSRF tokens for content restoration requests. An attacker can trick a logged-in administrator t...
CVE-2026-40326
- EPSS 0.16%
- Veröffentlicht 06.05.2026 20:16:32
- Zuletzt bearbeitet 06.05.2026 21:22:50
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the createBundle method in `csettings.cfc` does not properly validate anti-CSRF tokens for site bundle creation requests. An attacker can craft a malicious w...
CVE-2026-40174
- EPSS 0.17%
- Veröffentlicht 06.05.2026 20:16:31
- Zuletzt bearbeitet 06.05.2026 21:22:50
Masa CMS is a content management system forked from Mura CMS. In versions 7.5.2 and earlier, the cUsers.updateAddress function does not properly validate anti-CSRF tokens for user address management operations. An attacker can induce a logged-in adm...
CVE-2026-40332
- EPSS 0.33%
- Veröffentlicht 06.05.2026 20:13:18
- Zuletzt bearbeitet 06.05.2026 21:22:50
Masa CMS is affected by an Open Redirect vulnerability due to improper handling of scheme-relative URLs. The application incorrectly interprets paths beginning with double slashes (//) as internal paths, failing to validate the redirect target before...
CVE-2026-40331
- EPSS 0.32%
- Veröffentlicht 05.05.2026 20:16:39
- Zuletzt bearbeitet 05.05.2026 20:24:04
Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, the unauthenticated JSON API accepts an altTable parameter that is stored via the setAltTable()...
CVE-2026-40329
- EPSS 0.3%
- Veröffentlicht 05.05.2026 20:16:38
- Zuletzt bearbeitet 05.05.2026 20:24:04
Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's processing of the sortBy parameter. The application fails to proper...
CVE-2026-40330
- EPSS 0.43%
- Veröffentlicht 05.05.2026 20:16:38
- Zuletzt bearbeitet 05.05.2026 20:24:04
Masa CMS is an open source content management system. In versions 7.2.0 through 7.2.9, 7.3.0 through 7.3.14, 7.4.0 through 7.4.9, and 7.5.0 through 7.5.2, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function...
CVE-2025-66492
- EPSS 0.21%
- Veröffentlicht 12.12.2025 04:50:00
- Zuletzt bearbeitet 22.12.2025 18:46:26
Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerable to XSS when an unsanitized value of the ajax URL query parameter is ...
CVE-2024-32643
- EPSS 0.31%
- Veröffentlicht 03.12.2025 16:43:31
- Zuletzt bearbeitet 05.12.2025 15:37:39
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability...