Vulnerabilities (CVE)

Filtered by vendor Chshcms Subscribe
Filtered by product Mccms
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-5029 1 Chshcms 1 Mccms 2024-05-17 5.2 MEDIUM 8.8 HIGH
A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871.
CVE-2023-26782 1 Chshcms 1 Mccms 2024-02-04 N/A 6.5 MEDIUM
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
CVE-2023-26781 1 Chshcms 1 Mccms 2024-02-04 N/A 9.8 CRITICAL
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
CVE-2023-29815 1 Chshcms 1 Mccms 2024-02-04 N/A 8.8 HIGH
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).