Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 296 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.26% | — | Chshcms Mccms | 21/8/2025 | 17/6/2026 | MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands | |
| Analizada | Media (6.5) | 0.25% | — | Chshcms Mccms | 6/8/2025 | 17/6/2026 | MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded key Mc_Encryption_Key (bD2voYwPpNuJ7B8), defined in the db.php file.… | |
| Analizada | Media (5.5) | 0.21% | — | Chshcms Mccms | 14/7/2025 | 17/6/2026 | An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request. | |
| Analizada | Media (5.3) | 1.2% | — | Chshcms Mccms | 29/5/2025 | 17/6/2026 | A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/controllers/admin/Backups.php. The manipulation of the argument dirs leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed… | |
| Analizada | Media (5.3) | 0.52% | — | Chshcms Mccms | 29/5/2025 | 17/6/2026 | A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.64% | — | Chshcms Mccms | 17/9/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of… | |
| Modificada | Alta (8.8) | 0.70% | — | Chshcms Mccms | 14/6/2023 | 17/6/2026 | A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.70% | — | Chshcms Mccms | 14/6/2023 | 17/6/2026 | A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed… | |
| Modificada | Media (6.5) | 0.87% | — | Chshcms Mccms | 28/4/2023 | 17/6/2026 | An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. | |
| Modificada | Crítica (9.8) | 0.98% | — | Chshcms Mccms | 28/4/2023 | 17/6/2026 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | |
| Modificada | Alta (8.8) | 0.29% | — | Chshcms Mccms | 28/4/2023 | 17/6/2026 | mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). |