Mccms
Chshcms · 11 CVEs
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute a…
Aug 21, 2025
MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where…
Aug 6, 2025
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attac…
Jul 14, 2025
chshcms mccms Backups.php restore_del path traversal
May 29, 2025
chshcms mccms Gf.php index server-side request forgery
May 29, 2025
mccms 1 sql injection
Sep 17, 2023
mccms Comic.php pic_save server-side request forgery
Jun 14, 2023
mccms Comic.php pic_api server-side request forgery
Jun 14, 2023
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
Apr 28, 2023
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interfac…
Apr 28, 2023
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Read…
Apr 28, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-51818 | MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands | MEDIUM | 0.26% | Aug 21, 2025 |
| CVE-2025-50234 | MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic… | MEDIUM | 0.25% | Aug 6, 2025 |
| CVE-2025-51651 | An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a c… | MEDIUM | 0.21% | Jul 14, 2025 |
| CVE-2025-5328 | chshcms mccms Backups.php restore_del path traversal | MEDIUM | 1.21% | May 29, 2025 |
| CVE-2025-5327 | chshcms mccms Gf.php index server-side request forgery | MEDIUM | 0.52% | May 29, 2025 |
| CVE-2023-5029 | mccms 1 sql injection | HIGH | 0.64% | Sep 17, 2023 |
| CVE-2023-3236 | mccms Comic.php pic_save server-side request forgery | HIGH | 0.70% | Jun 14, 2023 |
| CVE-2023-3235 | mccms Comic.php pic_api server-side request forgery | HIGH | 0.70% | Jun 14, 2023 |
| CVE-2023-29815 | mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). | HIGH | 0.29% | Apr 28, 2023 |
| CVE-2023-26782 | An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configur… | MEDIUM | 0.87% | Apr 28, 2023 |
| CVE-2023-26781 | SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | CRITICAL | 0.98% | Apr 28, 2023 |
Showing 1 to 11 of 11 CVEs