« Volver al listado

Maccms

Maccms: vulnerabilidades y CVE

Maccms tiene 40 vulnerabilidades publicadas, 3 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE40
Últimos 12 meses3
Críticas6
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-75465Alta (7.5)0.75%—25 ago 2026
The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. The interface fails to perform any authentication or authorization checks. An unauthenticated remote…
CVE-2026-4563Baja (2.1)0.37%—23 mar 2026
A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This…
CVE-2026-4562Media (5.5)0.65%—23 mar 2026
A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing…
CVE-2025-10397Baja (2)0.34%—14 sept 2025
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can…
CVE-2025-10395Media (5.1)0.34%—14 sept 2025
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in…
CVE-2025-10122Baja (2)0.33%—9 sept 2025
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The…
CVE-2025-45474Alta (7.3)0.37%—29 may 2025
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
CVE-2025-45475Media (5.4)0.33%—27 may 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
CVE-2025-28091Crítica (9.1)0.44%—28 mar 2025
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
CVE-2025-28090Crítica (9.1)0.43%—28 mar 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
CVE-2025-28089Crítica (9.1)0.44%—28 mar 2025
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
CVE-2024-46654Media (4.8)0.25%—20 sept 2024
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
CVE-2024-32391Alta (7.3)0.92%—19 abr 2024
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
CVE-2022-47872Alta (8.8)0.87%—1 feb 2023
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address…
CVE-2022-44870Media (6.1)0.50%—6 ene 2023
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management…
CVE-2022-35148Media (6.5)0.69%—17 ago 2022
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
CVE-2022-31303Media (5.4)0.43%—21 jun 2022
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2022-31302Media (5.4)0.43%—21 jun 2022
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
CVE-2021-43707Media (6.1)0.64%—31 mar 2022
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
CVE-2022-27887Media (6.1)0.56%—25 mar 2022
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.
CVE-2022-27886Media (6.1)0.56%—25 mar 2022
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
CVE-2022-27885Media (6.1)0.56%—25 mar 2022
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.
CVE-2022-27884Media (6.1)0.56%—25 mar 2022
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.
CVE-2022-26573Media (6.1)0.57%—25 mar 2022
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.
CVE-2021-45787Media (5.4)0.46%—16 mar 2022
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
CVE-2021-45786Crítica (9.8)1.2%—16 mar 2022
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.
CVE-2020-21434Media (5.4)0.52%—4 oct 2021
Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.
CVE-2020-21387Media (6.1)0.57%—4 oct 2021
A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.
CVE-2020-21386Alta (8.8)0.44%—4 oct 2021
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.
CVE-2020-20514Alta (8.1)0.43%—24 sept 2021
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application5
  2. T1090 Proxy4
  3. T1005 Data from Local System1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Maccms