Maccms
Maccms: vulnerabilidades y CVE
Maccms tiene 40 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE40
Últimos 12 meses3
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-75465 | Alta (7.5) | 0.75% | — | 25 ago 2026 | The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote… |
| CVE-2026-4563 | Baja (2.1) | 0.37% | — | 23 mar 2026 | A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This… |
| CVE-2026-4562 | Media (5.5) | 0.65% | — | 23 mar 2026 | A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing… |
| CVE-2025-10397 | Baja (2) | 0.34% | — | 14 sept 2025 | A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can… |
| CVE-2025-10395 | Media (5.1) | 0.34% | — | 14 sept 2025 | A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in… |
| CVE-2025-10122 | Baja (2) | 0.33% | — | 9 sept 2025 | A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The… |
| CVE-2025-45474 | Alta (7.3) | 0.37% | — | 29 may 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings. |
| CVE-2025-45475 | Media (5.4) | 0.33% | — | 27 may 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management. |
| CVE-2025-28091 | Crítica (9.1) | 0.44% | — | 28 mar 2025 | maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article. |
| CVE-2025-28090 | Crítica (9.1) | 0.43% | — | 28 mar 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature. |
| CVE-2025-28089 | Crítica (9.1) | 0.44% | — | 28 mar 2025 | maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function. |
| CVE-2024-46654 | Media (4.8) | 0.25% | — | 20 sept 2024 | A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. |
| CVE-2024-32391 | Alta (7.3) | 0.92% | — | 19 abr 2024 | Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload. |
| CVE-2022-47872 | Alta (8.8) | 0.87% | — | 1 feb 2023 | A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address… |
| CVE-2022-44870 | Media (6.1) | 0.50% | — | 6 ene 2023 | A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management… |
| CVE-2022-35148 | Media (6.5) | 0.69% | — | 17 ago 2022 | maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html. |
| CVE-2022-31303 | Media (5.4) | 0.43% | — | 21 jun 2022 | maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. |
| CVE-2022-31302 | Media (5.4) | 0.43% | — | 21 jun 2022 | maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. |
| CVE-2021-43707 | Media (6.1) | 0.64% | — | 31 mar 2022 | Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter. |
| CVE-2022-27887 | Media (6.1) | 0.56% | — | 25 mar 2022 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter. |
| CVE-2022-27886 | Media (6.1) | 0.56% | — | 25 mar 2022 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter. |
| CVE-2022-27885 | Media (6.1) | 0.56% | — | 25 mar 2022 | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters. |
| CVE-2022-27884 | Media (6.1) | 0.56% | — | 25 mar 2022 | Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter. |
| CVE-2022-26573 | Media (6.1) | 0.57% | — | 25 mar 2022 | Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters. |
| CVE-2021-45787 | Media (5.4) | 0.46% | — | 16 mar 2022 | There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks. |
| CVE-2021-45786 | Crítica (9.8) | 1.2% | — | 16 mar 2022 | In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges. |
| CVE-2020-21434 | Media (5.4) | 0.52% | — | 4 oct 2021 | Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field. |
| CVE-2020-21387 | Media (6.1) | 0.57% | — | 4 oct 2021 | A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload. |
| CVE-2020-21386 | Alta (8.8) | 0.44% | — | 4 oct 2021 | A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges. |
| CVE-2020-20514 | Alta (8.1) | 0.43% | — | 24 sept 2021 | A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.