Vulnerabilities > Chshcms > High

DATE CVE VULNERABILITY TITLE RISK
2023-09-17 CVE-2023-5029 Unspecified vulnerability in Chshcms Mccms 2.6
A vulnerability, which was classified as critical, was found in mccms 2.6.
low complexity
chshcms
8.8
2023-06-14 CVE-2023-3235 Unspecified vulnerability in Chshcms Mccms
A vulnerability was found in mccms up to 2.6.5.
network
low complexity
chshcms
8.8
2023-06-14 CVE-2023-3236 Unspecified vulnerability in Chshcms Mccms
A vulnerability classified as critical has been found in mccms up to 2.6.5.
network
low complexity
chshcms
8.8
2023-04-28 CVE-2023-29815 Cross-Site Request Forgery (CSRF) vulnerability in Chshcms Mccms 2.6.3
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
network
low complexity
chshcms CWE-352
8.8
2022-05-26 CVE-2022-29661 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.
network
low complexity
chshcms CWE-89
7.2
2022-05-26 CVE-2022-29662 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.
network
low complexity
chshcms CWE-89
7.2
2022-05-26 CVE-2022-29663 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.
network
low complexity
chshcms CWE-89
7.2
2022-05-26 CVE-2022-29664 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.
network
low complexity
chshcms CWE-89
8.8
2022-05-26 CVE-2022-29665 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.
network
low complexity
chshcms CWE-89
7.2
2022-05-26 CVE-2022-29666 SQL Injection vulnerability in Chshcms Cscms Music Portal System 4.2
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
network
low complexity
chshcms CWE-89
7.2