Vulnerabilities > Chshcms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-17 | CVE-2023-5029 | SQL Injection vulnerability in Chshcms Mccms 2.6 A vulnerability, which was classified as critical, was found in mccms 2.6. | 8.8 |
2023-06-14 | CVE-2023-3235 | Server-Side Request Forgery (SSRF) vulnerability in Chshcms Mccms A vulnerability was found in mccms up to 2.6.5. | 8.8 |
2023-06-14 | CVE-2023-3236 | Server-Side Request Forgery (SSRF) vulnerability in Chshcms Mccms A vulnerability classified as critical has been found in mccms up to 2.6.5. | 8.8 |
2023-04-28 | CVE-2023-26781 | SQL Injection vulnerability in Chshcms Mccms 2.6 SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | 9.8 |
2023-04-28 | CVE-2023-26782 | Code Injection vulnerability in Chshcms Mccms 2.6.1 An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters. | 6.5 |
2023-04-28 | CVE-2023-29815 | Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Mccms 2.6.3 mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF). | 8.8 |
2022-06-09 | CVE-2022-30898 | Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Cscms 4.2 A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password. | 6.5 |
2022-05-26 | CVE-2022-29660 | SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | 9.8 |
2022-05-26 | CVE-2022-29661 | SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2 CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. | 7.2 |
2022-05-26 | CVE-2022-29662 | SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2 CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. | 7.2 |