Vulnerabilities > Chshcms > Mccms

DATE CVE VULNERABILITY TITLE RISK
2023-09-17 CVE-2023-5029 SQL Injection vulnerability in Chshcms Mccms 2.6
A vulnerability, which was classified as critical, was found in mccms 2.6.
low complexity
chshcms CWE-89
8.8
2023-06-14 CVE-2023-3235 Server-Side Request Forgery (SSRF) vulnerability in Chshcms Mccms
A vulnerability was found in mccms up to 2.6.5.
network
low complexity
chshcms CWE-918
8.8
2023-06-14 CVE-2023-3236 Server-Side Request Forgery (SSRF) vulnerability in Chshcms Mccms
A vulnerability classified as critical has been found in mccms up to 2.6.5.
network
low complexity
chshcms CWE-918
8.8
2023-04-28 CVE-2023-26781 SQL Injection vulnerability in Chshcms Mccms 2.6
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
network
low complexity
chshcms CWE-89
critical
9.8
2023-04-28 CVE-2023-26782 Code Injection vulnerability in Chshcms Mccms 2.6.1
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
network
low complexity
chshcms CWE-94
6.5
2023-04-28 CVE-2023-29815 Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Mccms 2.6.3
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
network
low complexity
chshcms CWE-352
8.8