« Volver al listado

Sscms

Sscms Siteserver CMS: vulnerabilidades y CVE

Sscms Siteserver CMS tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE10
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-45529Alta (7.1)0.36%—27 may 2025
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
CVE-2023-2862Media (6.1)0.56%—24 may 2023
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to…
CVE-2022-44299Media (4.9)0.83%—16 feb 2023
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
CVE-2022-44298Crítica (9.8)0.74%—27 ene 2023
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
CVE-2022-44297Crítica (9.8)0.97%—26 ene 2023
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
CVE-2022-30349Media (6.1)0.68%—2 jun 2022
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
CVE-2021-42656Media (5.4)0.70%—24 may 2022
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
CVE-2021-42655Alta (8.8)1.2%—24 may 2022
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
CVE-2021-42654Crítica (9.8)1.7%—24 may 2022
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
CVE-2022-28118Crítica (9.8)2.8%—3 may 2022
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

Otros productos de Sscms