« Volver al listado

Murasoftware

Murasoftware Mura CMS: vulnerabilidades y CVE

Murasoftware Mura CMS tiene 9 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE9
Últimos 12 meses8
Críticas3
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-67830Crítica (9.8)0.32%—18 mar 2026
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
CVE-2025-67829Crítica (9.8)0.26%—18 mar 2026
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
CVE-2025-55046Alta (8.1)0.12%—18 mar 2026
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks…
CVE-2025-55045Alta (7.1)0.11%—18 mar 2026
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling…
CVE-2025-55044Alta (8.8)0.13%—18 mar 2026
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token…
CVE-2025-55043Media (6.5)0.16%—18 mar 2026
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force administrators to create and save site…
CVE-2025-55041Alta (8)0.13%—18 mar 2026
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group…
CVE-2025-55040Alta (8.8)0.16%—18 mar 2026
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token…
CVE-2022-47003Crítica (9.8)3.6%—1 feb 2023
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1203 Exploitation for Client Execution5
  2. T1005 Data from Local System2
  3. T1190 Exploit Public-Facing Application2
  4. T1098 Account Manipulation1
  5. T1185 Browser Session Hijacking1
  6. T1565.001 Stored Data Manipulation1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.