VendorsCHSHCMSmccmsall versions
Vulnerabilities

CHSHCMS MCCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2023-26781
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.
Published 2023-04-28 · Modified
9.8EPSS 0.010
CVE-2025-5328
chshcms mccms Backups.php restore_del path traversal
Published 2025-05-29 · Analyzed
8.8EPSS 0.012
CVE-2023-3235
mccms Comic.php pic_api server-side request forgery
Published 2023-06-14 · Modified
8.8EPSS 0.007
CVE-2023-3236
mccms Comic.php pic_save server-side request forgery
Published 2023-06-14 · Modified
8.8EPSS 0.007
CVE-2023-5029
mccms 1 sql injection
Published 2023-09-17 · Modified
8.8EPSS 0.006
CVE-2025-5327
chshcms mccms Gf.php index server-side request forgery
Published 2025-05-29 · Analyzed
8.8EPSS 0.005
CVE-2023-29815
mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).
Published 2023-04-28 · Modified
8.8EPSS 0.003
CVE-2023-26782
An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.
Published 2023-04-28 · Modified
6.5EPSS 0.009
CVE-2025-50234
MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded key Mc_Encryption_Key (bD2voYwPpNuJ7B8), defined in the db.php file. The decrypted URL is passed to the geturl() method, which uses cURL to make a request to the URL without proper security checks. An attacker can craft a malicious encrypted pic parameter, which, when decrypted, points to internal addresses or local file paths (such as http://127.0.0.1 or file://). By using the file:// protocol, the attacker can access arbitrary files on the local file system (e.g., file:///etc/passwd, file:///C:/Windows/System32/drivers/etc/hosts), allowing them to read sensitive configuration files, log files, and more, leading to information leakage or system exposure. The danger of this SSRF vulnerability includes accessing internal services and local file systems through protocols like http://, ftp://, and file://, which can result in sensitive data leakage, remote code execution, privilege escalation, or full system compromise, severely affecting the system's security and stability.
Published 2025-08-06 · Analyzed
6.5EPSS 0.002
CVE-2025-51651
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.
Published 2025-07-14 · Analyzed
5.5EPSS 0.002
CVE-2025-51818
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands
Published 2025-08-21 · Analyzed
5.4EPSS 0.003