MaccmsCVEs & Vulnerabilities

37 CVEs affecting Maccms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

maccms 37
CVE-2025-10397HIGH

A vulnerability was identified in Magicblack MacCMS 2025.1000.4050. This affects an unknown part of the component API Handler. The manipulation of the argument cjurl leads to server-side request forgery. The attack can be initiated remotely. The exploit is publicly available and might be used.

14 Sep 2025
7.2
CVSS
CVE-2025-10395HIGH

A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the attack remotely.

14 Sep 2025
7.2
CVSS
CVE-2025-10122HIGH

A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

9 Sep 2025
7.2
CVSS
CVE-2025-45474HIGH

maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

29 May 2025
7.3
CVSS
CVE-2025-45475MEDIUM

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

27 May 2025
5.4
CVSS
CVE-2025-28091CRITICAL

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

29 Mar 2025
9.1
CVSS
CVE-2025-28090CRITICAL

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) in the Collection Custom Interface feature.

29 Mar 2025
9.1
CVSS
CVE-2025-28089CRITICAL

maccms10 v2025.1000.4047 is vulnerable to Server-Side Request Forgery (SSRF) via the Scheduled Task function.

29 Mar 2025
9.1
CVSS
CVE-2024-46654MEDIUM

A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

20 Sep 2024
4.8
CVSS
CVE-2024-32391HIGH

Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

20 Apr 2024
7.3
CVSS
CVE-2022-47872HIGH

A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.

2 Feb 2023
8.8
CVSS
CVE-2022-44870MEDIUM

A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

6 Jan 2023
6.1
CVSS
CVE-2022-35148MEDIUM

maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

18 Aug 2022
6.5
CVSS
CVE-2022-31303MEDIUM

maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

21 Jun 2022
5.4
CVSS
CVE-2022-31302MEDIUM

maccms8 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

21 Jun 2022
5.4
CVSS
CVE-2021-43707MEDIUM

Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

31 Mar 2022
6.1
CVSS
CVE-2022-27887MEDIUM

Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/vod/data.html via the repeat parameter.

25 Mar 2022
6.1
CVSS
CVE-2022-27886MEDIUM

Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/ulog/index.html via the wd parameter.

25 Mar 2022
6.1
CVSS
CVE-2022-27885MEDIUM

Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/website/data.html via the select and input parameters.

25 Mar 2022
6.1
CVSS
CVE-2022-27884MEDIUM

Maccms v10 was discovered to contain a reflected cross-site scripting (XSS) vulnerability in /admin.php/admin/plog/index.html via the wd parameter.

25 Mar 2022
6.1
CVSS
CVE-2022-26573MEDIUM

Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.

25 Mar 2022
6.1
CVSS
CVE-2021-45787MEDIUM

There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.

16 Mar 2022
5.4
CVSS
CVE-2021-45786CRITICAL

In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

16 Mar 2022
9.8
CVSS
CVE-2020-21434MEDIUM

Maccms 10 contains a cross-site scripting (XSS) vulnerability in the Editing function under the Member module. This vulnerability is exploited via a crafted payload in the nickname text field.

5 Oct 2021
5.4
CVSS
CVE-2020-21387MEDIUM

A cross-site scripting (XSS) vulnerability in the parameter type_en of Maccms 10 allows attackers to obtain the administrator cookie and escalate privileges via a crafted payload.

4 Oct 2021
6.1
CVSS
CVE-2020-21386HIGH

A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.

4 Oct 2021
8.8
CVSS
CVE-2020-20514HIGH

A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/<id>.html allows authenticated attackers to delete all users.

25 Sep 2021
8.1
CVSS
CVE-2020-21082MEDIUM

A cross-site scripting (XSS) vulnerability in the background administrator article management module of Maccms 8.0 allows attackers to steal administrator and user cookies via crafted payloads in the text fields for Chinese and English names.

14 Sep 2021
6.1
CVSS
CVE-2020-21081MEDIUM

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

14 Sep 2021
6.5
CVSS
CVE-2020-21363MEDIUM

An arbitrary file deletion vulnerability exists within Maccms10.

12 Aug 2021
6.5
CVSS
CVE-2020-21362MEDIUM

A cross site scripting (XSS) vulnerability in the background search function of Maccms10 allows attackers to execute arbitrary web scripts or HTML via the 'wd' parameter.

12 Aug 2021
5.4
CVSS
CVE-2020-21359CRITICAL

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

12 Aug 2021
9.8
CVSS
CVE-2018-19465MEDIUM

Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.

7 Jun 2019
6.1
CVSS
CVE-2019-9829HIGH

Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.

15 Mar 2019
8.8
CVSS
CVE-2019-8410MEDIUM

Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key).

27 Feb 2019
6.1
CVSS
CVE-2018-12114HIGHpoc

Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

14 Jun 2018
8.8
CVSS
CVE-2017-17733CRITICAL

Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

18 Dec 2017
9.8
CVSS
← PrevPage 1 / 1Next →
Maccms CVEs & Vulnerabilities — 37 Tracked