Chshcms
Chshcms Mccms: vulnerabilidades y CVE
Chshcms Mccms tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-51818 | Media (5.4) | 0.26% | — | 21 ago 2025 | MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands |
| CVE-2025-50234 | Media (6.5) | 0.25% | — | 6 ago 2025 | MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1)… |
| CVE-2025-51651 | Media (5.5) | 0.19% | — | 14 jul 2025 | An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request. |
| CVE-2025-5328 | Media (5.3) | 1.2% | — | 29 may 2025 | A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/controllers/admin/Backups.php. The manipulation of the argument… |
| CVE-2025-5327 | Media (5.3) | 0.52% | — | 29 may 2025 | A vulnerability was found in chshcms mccms 2.7. It has been classified as critical. This affects the function index of the file sys/apps/controllers/api/Gf.php. The manipulation of the argument pic leads to server-side… |
| CVE-2023-5029 | Alta (8.8) | 0.64% | — | 17 sept 2023 | A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql… |
| CVE-2023-3236 | Alta (8.8) | 0.70% | — | 14 jun 2023 | A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side… |
| CVE-2023-3235 | Alta (8.8) | 0.70% | — | 14 jun 2023 | A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads… |
| CVE-2023-26782 | Media (6.5) | 0.87% | — | 28 abr 2023 | An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. |
| CVE-2023-26781 | Crítica (9.8) | 0.98% | — | 28 abr 2023 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. |
| CVE-2023-29815 | Alta (8.8) | 0.29% | — | 28 abr 2023 | mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). |