« Volver al listado

Wangl1989

Wangl1989 Mysiteforme: vulnerabilidades y CVE

Wangl1989 Mysiteforme tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses0
Críticas4
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-26136Crítica (9.8)0.40%—4 mar 2025
A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.
CVE-2024-57767Alta (8.6)0.44%—15 ene 2025
MSFM before v2025.01.01 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /file/download.
CVE-2024-57766Crítica (9.1)0.51%—15 ene 2025
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/editField.
CVE-2024-57765Alta (7.5)0.45%—15 ene 2025
MSFM before 2025.01.01 was discovered to contain a SQL injection vulnerability via the s_name parameter at table/list.
CVE-2024-57764Crítica (9.1)0.51%—15 ene 2025
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/add.
CVE-2024-57763Crítica (9.1)0.51%—15 ene 2025
MSFM before 2025.01.01 was discovered to contain a fastjson deserialization vulnerability via the component system/table/addField.
CVE-2024-57762Alta (7.5)0.51%—15 ene 2025
MSFM before v2025.01.01 was discovered to contain a deserialization vulnerability via the pom.xml configuration file.
CVE-2024-13139Media (5.3)0.56%—5 ene 2025
A vulnerability was found in wangl1989 mysiteforme 1.0. It has been rated as critical. This issue affects the function doContent of the file src/main/java/com/mysiteform/admin/controller/system/FileController. The…
CVE-2024-13138Media (5.1)0.44%—5 ene 2025
A vulnerability was found in wangl1989 mysiteforme 1.0. It has been declared as critical. This vulnerability affects the function upload of the file src/main/java/com/mysiteform/admin/service/ipl/LocalUploadServiceImpl.…
CVE-2024-13137Media (5.1)0.34%—5 ene 2025
A vulnerability was found in wangl1989 mysiteforme 1.0. It has been classified as problematic. This affects the function RestResponse of the file src/main/java/com/mysiteforme/admin/controller/system/SiteController. The…
CVE-2024-13136Media (5.3)0.60%—5 ene 2025
A vulnerability was found in wangl1989 mysiteforme 1.0 and classified as critical. Affected by this issue is the function rememberMeManager of the file src/main/java/com/mysiteforme/admin/config/ShiroConfig.java. The…
CVE-2022-29309Alta (7.5)0.91%—24 may 2022
mysiteforme v2.2.1 was discovered to contain a Server-Side Request Forgery.
CVE-2021-46026Media (5.4)0.44%—20 ene 2022
mysiteforme, as of 19-12-2022, is vulnerable to Cross Site Scripting (XSS) via the add blog tag function in the blog tag in the background blog management.
CVE-2021-46027Media (6.5)0.42%—19 ene 2022
mysiteforme, as of 19-12-2022, has a CSRF vulnerability in the background blog management. The attacker constructs a CSRF load. Once the administrator clicks a malicious link, a blog tag will be added

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application7
  2. T1059 Command and Scripting Interpreter4
  3. T1005 Data from Local System2
  4. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.