← Back

Maccms

maccms

37 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Maccms
maccms

CVEs (37)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Maccms
1Maccms
Apr 29, 2026
Sep 14, 2025
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can b...Show more
A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used.Show less
1Maccms
1Maccms
Oct 8, 2025
Sep 14, 2025
5.1 MEDIUM· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in serv...Show more
A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the attack remotely.Show less
1Maccms
1Maccms
Apr 29, 2026
Sep 9, 2025
2.0 LOW· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack...Show more
A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.Show less
1Maccms
1Maccms
Jun 19, 2025
May 29, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.
1Maccms
1Maccms
Jun 24, 2025
May 27, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.
1Maccms
1Maccms
Apr 7, 2025
Mar 28, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.
1Maccms
1Maccms
Apr 7, 2025
Mar 28, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.
1Maccms
1Maccms
Apr 7, 2025
Mar 28, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.
1Maccms
1Maccms
Apr 28, 2025
Sep 20, 2024
N/A· v4
4.8 MEDIUM· v3
N/A· v2
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
1Maccms
1Maccms
Apr 30, 2025
Apr 19, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.
1Maccms
1Maccms
Nov 21, 2024
Feb 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address mod...Show more
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.Show less
1Maccms
1Maccms
Apr 9, 2025
Jan 6, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management mo...Show more
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.Show less
1Maccms
1Maccms
Nov 21, 2024
Aug 17, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.
1Maccms
1Maccms
Nov 21, 2024
Jun 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
1Maccms
1Maccms
Nov 21, 2024
Jun 21, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
1Maccms
1Maccms
Nov 21, 2024
Mar 31, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.
1Maccms
1Maccms
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.
1Maccms
1Maccms
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.
1Maccms
1Maccms
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.
1Maccms
1Maccms
Nov 21, 2024
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.