S-cmsCVEs & Vulnerabilities

42 CVEs affecting S-cms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

s-cms 47cms enterprise website construction system 1
CVE-2023-29962MEDIUM

S-CMS v5.0 was discovered to contain an arbitrary file read vulnerability.

4 Jan 2024
6.5
CVSS
CVE-2023-7191HIGH

A vulnerability, which was classified as critical, was found in S-CMS up to 2.0_build20220529-20231006. This affects an unknown part of the file member/reg.php. The manipulation of the argument M_login/M_email leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier VDB-249393 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

31 Dec 2023
8.8
CVSS
CVE-2023-7190HIGH

A vulnerability, which was classified as critical, has been found in S-CMS up to 2.0_build20220529-20231006. Affected by this issue is some unknown functionality of the file /member/ad.php?action=ad. The manipulation of the argument A_text/A_url/A_contact leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-249392. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

31 Dec 2023
8.8
CVSS
CVE-2023-7189HIGH

A vulnerability classified as critical was found in S-CMS up to 2.0_build20220529-20231006. Affected by this vulnerability is an unknown functionality of the file /s/index.php?action=statistics. The manipulation of the argument lid leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-249391. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

31 Dec 2023
8.8
CVSS
CVE-2023-51052CRITICAL

S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_formauth parameter at /admin/ajax.php.

21 Dec 2023
9.8
CVSS
CVE-2023-51051CRITICAL

S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_textauth parameter at /admin/ajax.php.

21 Dec 2023
9.8
CVSS
CVE-2023-51050CRITICAL

S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_productauth parameter at /admin/ajax.php.

21 Dec 2023
9.8
CVSS
CVE-2023-51049CRITICAL

S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php.

21 Dec 2023
9.8
CVSS
CVE-2023-51048CRITICAL

S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_newsauth parameter at /admin/ajax.php.

21 Dec 2023
9.8
CVSS
CVE-2023-29963HIGH

S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.

6 May 2023
7.2
CVSS
CVE-2022-4377MEDIUM

A vulnerability was found in S-CMS 5.0 Build 20220328. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Contact Information Page. The manipulation of the argument Make a Call leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-215197 was assigned to this vulnerability.

9 Dec 2022
5.4
CVSS
CVE-2022-23336CRITICAL

S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter.

15 Feb 2022
9.8
CVSS
CVE-2020-20426MEDIUM

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in /function/booksave.php.

23 Dec 2021
6.1
CVSS
CVE-2020-20425MEDIUM

S-CMS Government Station Building System v5.0 contains a cross-site scripting (XSS) vulnerability in the search function.

23 Dec 2021
6.1
CVSS
CVE-2020-19954HIGH

An XML External Entity (XXE) vulnerability was discovered in /api/notify.php in S-CMS 3.0 which allows attackers to read arbitrary files.

14 Oct 2021
7.5
CVSS
CVE-2021-37270CRITICAL

There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified background path without logging in to the background to obtain the background administrator authority.

28 Sep 2021
9.8
CVSS
CVE-2020-19158MEDIUM

Cross Site Scripting (XSS) in S-CMS build 20191014 and earlier allows remote attackers to execute arbitrary code via the 'Site Title' parameter of the component '/data/admin/#/app/config/'.

15 Sep 2021
5.4
CVSS
CVE-2020-20340HIGH

A SQL injection vulnerability in the 4.edu.php\conn\function.php component of S-CMS v1.0 allows attackers to access sensitive database information.

1 Sep 2021
7.5
CVSS
CVE-2020-19046MEDIUM

Cross Site Scripting (XSS) in S-CMS v1.0 allows remote attackers to execute arbitrary code via the component '/admin/tpl.php?page='.

31 Aug 2021
5.4
CVSS
CVE-2020-20701MEDIUM

A stored cross site scripting (XSS) vulnerability in /app/config/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

30 Jul 2021
4.8
CVSS
CVE-2020-20700MEDIUM

A stored cross site scripting (XSS) vulnerability in /app/form_add/of S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Title Entry text box.

30 Jul 2021
4.8
CVSS
CVE-2020-20699MEDIUM

A cross site scripting (XSS) vulnerability in S-CMS PHP v3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the Copyright text box under Basic Settings.

30 Jul 2021
4.8
CVSS
CVE-2020-20698HIGH

A remote code execution (RCE) vulnerability in /1.com.php of S-CMS PHP v3.0 allows attackers to getshell via modification of a PHP file.

30 Jul 2021
7.2
CVSS
CVE-2019-17368MEDIUM

S-CMS v1.5 has XSS in tpl.php via the member/member_login.php from parameter.

9 Oct 2019
6.1
CVSS
CVE-2019-16312MEDIUM

s-cms V3.0 has XSS in index.php?type=text via the S_id parameter.

14 Sep 2019
6.1
CVSS
CVE-2019-10708CRITICAL

S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter.

2 Apr 2019
9.8
CVSS
CVE-2019-10237HIGH

S-CMS PHP v1.0 has a CSRF vulnerability to add a new admin user via the 4.edu.php/admin/ajax.php?type=admin&action=add&lang=0 URI, a related issue to CVE-2019-9040.

27 Mar 2019
8.8
CVSS
CVE-2019-9925MEDIUM

S-CMS PHP v1.0 has XSS in 4.edu.php via the S_id parameter.

22 Mar 2019
6.1
CVSS
CVE-2019-9040HIGH

S-CMS PHP v3.0 has a CSRF vulnerability to add a new admin user via the admin/ajax.php?type=admin&action=add URI, a related issue to CVE-2018-19332.

23 Feb 2019
8.8
CVSS
CVE-2019-6805CRITICAL

SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter.

25 Jan 2019
9.8
CVSS
CVE-2018-20480CRITICAL

An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.

26 Dec 2018
9.8
CVSS
CVE-2018-20479CRITICAL

An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.

26 Dec 2018
9.8
CVSS
CVE-2018-20478HIGH

An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.

26 Dec 2018
7.5
CVSS
CVE-2018-20477CRITICAL

An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.

26 Dec 2018
9.8
CVSS
CVE-2018-20476MEDIUM

An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter.

26 Dec 2018
6.1
CVSS
CVE-2018-20018HIGH

S-CMS V3.0 has SQL injection via the S_id parameter, as demonstrated by the /1/?type=productinfo&S_id=140 URI.

10 Dec 2018
7.5
CVSS
CVE-2018-19332HIGH

An issue was discovered in S-CMS v1.5. There is a CSRF vulnerability that can add a new user via the admin/ajax.php?type=member&action=add URI.

17 Nov 2018
8.8
CVSS
CVE-2018-19331HIGH

An issue was discovered in S-CMS v1.5. There is a SQL injection vulnerability in search.php via the keyword parameter.

17 Nov 2018
7.5
CVSS
CVE-2018-19145MEDIUM

An issue was discovered in S-CMS v1.5. There is an XSS vulnerability in search.php via the keyword parameter.

10 Nov 2018
6.1
CVSS
CVE-2018-18887CRITICAL

S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).

1 Nov 2018
9.8
CVSS
CVE-2018-18427CRITICAL

s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php.

17 Oct 2018
9.8
CVSS
CVE-2018-18426HIGH

s-cms 3.0 allows remote attackers to execute arbitrary PHP code by placing this code in a crafted User-agent Disallow value in the robots.php txt parameter.

17 Oct 2018
8.8
CVSS
← PrevPage 1 / 1Next →
S-cms CVEs & Vulnerabilities — 42 Tracked