SscmsCVEs & Vulnerabilities

12 CVEs affecting Sscms products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

siteserver cms 10sscms 2
CVE-2025-52237MEDIUM

An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

6 Aug 2025
6.5
CVSS
CVE-2025-45529HIGH

An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.

27 May 2025
7.1
CVSS
CVE-2023-43953MEDIUM

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

4 Oct 2023
5.4
CVSS
CVE-2023-2862MEDIUM

A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-229818 is the identifier assigned to this vulnerability.

24 May 2023
6.1
CVSS
CVE-2022-44299MEDIUM

SiteServerCMS 7.1.3 sscms has a file read vulnerability.

17 Feb 2023
4.9
CVSS
CVE-2022-44298CRITICAL

SiteServer CMS 7.1.3 is vulnerable to SQL Injection.

27 Jan 2023
9.8
CVSS
CVE-2022-44297CRITICAL

SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.

27 Jan 2023
9.8
CVSS
CVE-2022-30349MEDIUM

siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).

2 Jun 2022
6.1
CVSS
CVE-2021-42656MEDIUM

SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.

24 May 2022
5.4
CVSS
CVE-2021-42655HIGH

SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.

24 May 2022
8.8
CVSS
CVE-2021-42654CRITICAL

SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

24 May 2022
9.8
CVSS
CVE-2022-28118CRITICAL

SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

3 May 2022
9.8
CVSS
← PrevPage 1 / 1Next →