Masacms

Masacms

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 12.12.2025 04:50:00
  • Zuletzt bearbeitet 22.12.2025 18:46:26

Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerable to XSS when an unsanitized value of the ajax URL query parameter is ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 03.12.2025 16:43:31
  • Zuletzt bearbeitet 05.12.2025 15:37:39

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS will render the page regardless of group restrictions. This vulnerability...

Exploit
  • EPSS 0.03%
  • Veröffentlicht 03.12.2025 16:37:53
  • Zuletzt bearbeitet 05.12.2025 15:36:02

Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via password reset email. This vulnerability is fixed in 7.2.8, 7.3.13, a...

Exploit
  • EPSS 0.98%
  • Veröffentlicht 03.12.2025 16:26:00
  • Zuletzt bearbeitet 05.12.2025 14:47:50

Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via the criter...

  • EPSS 93.72%
  • Veröffentlicht 11.08.2025 21:15:26
  • Zuletzt bearbeitet 03.12.2025 16:15:54

MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versi...

Exploit
  • EPSS 72.43%
  • Veröffentlicht 01.02.2023 14:15:08
  • Zuletzt bearbeitet 21.11.2024 07:31:23

A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

Exploit
  • EPSS 51.01%
  • Veröffentlicht 05.05.2022 14:15:07
  • Zuletzt bearbeitet 21.11.2024 06:27:22

MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.