74cmsCVEs & Vulnerabilities

36 CVEs affecting 74cms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

74cmsse 1974cms 17
CVE-2020-22208KEVCRITICALin the wild

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

11 Apr 2026
9.8
CVSS
CVE-2020-22211KEVCRITICALin the wild

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

11 Apr 2026
9.8
CVSS
CVE-2020-29279KEVCRITICALin the wild

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

11 Apr 2026
9.8
CVSS
CVE-2025-4329MEDIUM

A vulnerability was found in 74CMS up to 3.33.0. It has been rated as problematic. Affected by this issue is the function index of the file /index.php/index/download/index. The manipulation of the argument url leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

6 May 2025
4.3
CVSS
CVE-2024-46089MEDIUM

74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.

18 Apr 2025
6.3
CVSS
CVE-2024-2561HIGH

A vulnerability, which was classified as critical, has been found in 74CMS 3.28.0. Affected by this issue is the function sendCompanyLogo of the file /controller/company/Index.php#sendCompanyLogo of the component Company Logo Handler. The manipulation of the argument imgBase64 leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-257060.

17 Mar 2024
8.8
CVSS
CVE-2022-42154CRITICAL

An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

17 Oct 2022
9.8
CVSS
CVE-2022-41472MEDIUM

74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

17 Oct 2022
5.4
CVSS
CVE-2022-41471MEDIUM

74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.

17 Oct 2022
6.5
CVSS
CVE-2022-33097HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

23 Jun 2022
7.5
CVSS
CVE-2022-33096HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.

23 Jun 2022
7.5
CVSS
CVE-2022-33095HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

23 Jun 2022
7.5
CVSS
CVE-2022-33094HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.

23 Jun 2022
7.5
CVSS
CVE-2022-33093HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.

23 Jun 2022
7.5
CVSS
CVE-2022-33092HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.

23 Jun 2022
7.5
CVSS
CVE-2022-32131MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show.

23 Jun 2022
6.1
CVSS
CVE-2022-32130MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_resume/total/nature.

23 Jun 2022
6.1
CVSS
CVE-2022-32129MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/safety/trade.

23 Jun 2022
6.1
CVSS
CVE-2022-32128MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im.

23 Jun 2022
6.1
CVSS
CVE-2022-32127MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

23 Jun 2022
6.1
CVSS
CVE-2022-32126MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.

23 Jun 2022
6.1
CVSS
CVE-2022-32125MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.

23 Jun 2022
6.1
CVSS
CVE-2022-32124MEDIUM

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/.

23 Jun 2022
6.1
CVSS
CVE-2022-29721HIGH

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

26 May 2022
7.5
CVSS
CVE-2022-29720HIGH

74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.

26 May 2022
7.5
CVSS
CVE-2022-26271HIGH

74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

28 Mar 2022
7.5
CVSS
CVE-2020-22421MEDIUM

74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.

8 Dec 2021
6.1
CVSS
CVE-2020-22212CRITICAL

SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.

16 Jun 2021
9.8
CVSS
CVE-2020-22210CRITICAL

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

16 Jun 2021
9.8
CVSS
CVE-2020-22209CRITICAL

SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

16 Jun 2021
9.8
CVSS
CVE-2020-35339CRITICAL

In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.

17 Feb 2021
9.8
CVSS
CVE-2019-17612HIGH

An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.

16 Oct 2019
7.2
CVSS
CVE-2019-11374HIGHpoc

74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

20 Apr 2019
8.8
CVSS
CVE-2019-10684CRITICAL

Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter.

1 Apr 2019
9.8
CVSS
CVE-2018-20519HIGH

An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter.

27 Dec 2018
8.1
CVSS
CVE-2018-20454MEDIUM

An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter.

25 Dec 2018
6.1
CVSS
← PrevPage 1 / 1Next →