Murasoftware
Murasoftware Mura CMS: vulnerabilidades y CVE
Murasoftware Mura CMS tiene 9 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses8
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-67830 | Crítica (9.8) | 0.32% | — | 18 mar 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. |
| CVE-2025-67829 | Crítica (9.8) | 0.26% | — | 18 mar 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. |
| CVE-2025-55046 | Alta (8.1) | 0.12% | — | 18 mar 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The vulnerable cTrash.empty function lacks… |
| CVE-2025-55045 | Alta (7.1) | 0.11% | — | 18 mar 2026 | The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function lacks CSRF token validation, enabling… |
| CVE-2025-55044 | Alta (8.8) | 0.13% | — | 18 mar 2026 | The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cTrash.restore function lacks CSRF token… |
| CVE-2025-55043 | Media (6.5) | 0.16% | — | 18 mar 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force administrators to create and save site… |
| CVE-2025-55041 | Alta (8) | 0.13% | — | 18 mar 2026 | MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privileges by adding any user to any group… |
| CVE-2025-55040 | Alta (8.8) | 0.16% | — | 18 mar 2026 | The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importform function lacks CSRF token… |
| CVE-2022-47003 | Crítica (9.8) | 3.6% | — | 1 feb 2023 | A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.