CVE-2025-51818
- EPSS 0.09%
- Veröffentlicht 21.08.2025 00:00:00
- Zuletzt bearbeitet 24.09.2025 00:02:49
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands
CVE-2025-50234
- EPSS 0.11%
- Veröffentlicht 06.08.2025 15:15:32
- Zuletzt bearbeitet 18.08.2025 15:38:30
MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded k...
CVE-2025-51651
- EPSS 0.04%
- Veröffentlicht 14.07.2025 00:00:00
- Zuletzt bearbeitet 17.07.2025 13:27:40
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.
CVE-2025-5328
- EPSS 0.11%
- Veröffentlicht 29.05.2025 21:00:06
- Zuletzt bearbeitet 10.06.2025 15:14:10
A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/controllers/admin/Backups.php. The manipulation of the argument dirs leads to path traversal. ...
CVE-2025-5327
- EPSS 0.1%
- Veröffentlicht 29.05.2025 20:31:04
- Zuletzt bearbeitet 10.06.2025 15:13:37
A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php. The manipulation of the argument pic leads to server-side request forgery. It is possible...
CVE-2023-5029
- EPSS 0.03%
- Veröffentlicht 17.09.2023 22:15:46
- Zuletzt bearbeitet 21.11.2024 08:40:55
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been di...
CVE-2023-3235
- EPSS 0.06%
- Veröffentlicht 14.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery....
CVE-2023-3236
- EPSS 0.06%
- Veröffentlicht 14.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:45
A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible...
CVE-2023-26781
- EPSS 0.34%
- Veröffentlicht 28.04.2023 20:15:13
- Zuletzt bearbeitet 31.01.2025 17:15:10
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
CVE-2023-26782
- EPSS 0.31%
- Veröffentlicht 28.04.2023 20:15:13
- Zuletzt bearbeitet 31.01.2025 17:15:10
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.