Vulnerabilities > Sscms > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-01-27 CVE-2022-44298 SQL Injection vulnerability in Sscms Siteserver CMS 7.1.3
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
network
low complexity
sscms CWE-89
critical
9.8
2023-01-26 CVE-2022-44297 SQL Injection vulnerability in Sscms Siteserver CMS 7.1.3
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
network
low complexity
sscms CWE-89
critical
9.8
2022-05-24 CVE-2021-42654 Unrestricted Upload of File with Dangerous Type vulnerability in Sscms Siteserver CMS
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
network
low complexity
sscms CWE-434
critical
9.8
2022-05-03 CVE-2022-28118 Unspecified vulnerability in Sscms Siteserver CMS
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
network
low complexity
sscms
critical
9.8