CVE-2026-4563
- EPSS 0.03%
- Veröffentlicht 22.03.2026 23:51:03
- Zuletzt bearbeitet 23.03.2026 14:31:37
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument orde...
CVE-2026-4562
- EPSS 0.1%
- Veröffentlicht 22.03.2026 23:09:08
- Zuletzt bearbeitet 23.03.2026 14:31:37
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be...
CVE-2025-10397
- EPSS 0.05%
- Veröffentlicht 14.09.2025 11:02:05
- Zuletzt bearbeitet 08.10.2025 14:24:16
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The expl...
CVE-2025-10395
- EPSS 0.05%
- Veröffentlicht 14.09.2025 08:15:29
- Zuletzt bearbeitet 08.10.2025 14:24:08
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is...
CVE-2025-10122
- EPSS 0.03%
- Veröffentlicht 09.09.2025 02:32:07
- Zuletzt bearbeitet 08.10.2025 14:23:59
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. Th...
CVE-2025-45474
- EPSS 0.32%
- Veröffentlicht 29.05.2025 00:00:00
- Zuletzt bearbeitet 19.06.2025 00:45:23
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
CVE-2025-45475
- EPSS 0.23%
- Veröffentlicht 27.05.2025 00:00:00
- Zuletzt bearbeitet 29.05.2025 19:15:27
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
CVE-2025-28089
- EPSS 0.29%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:20:46
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
CVE-2025-28090
- EPSS 0.29%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:18:13
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
CVE-2025-28091
- EPSS 0.29%
- Veröffentlicht 28.03.2025 00:00:00
- Zuletzt bearbeitet 07.04.2025 14:17:00
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.