📦 Masacms

by Masacms

🔍 What is Masacms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-32641

CRITICAL CVSS 9.8 Dec 3, 2025

CVE-2024-32641 is a critical remote code execution vulnerability in Masa CMS that allows unauthenticated attackers to execute arbitrary code on affected systems. The vulnerability exists in the addPar...

CVE-2022-47002

CRITICAL CVSS 9.8 Feb 1, 2023

This vulnerability allows attackers to bypass authentication in Masa CMS by exploiting a flaw in the Remember Me function. Attackers can gain unauthorized access to administrative panels and user acco...

CVE-2025-66492

HIGH CVSS 8.2 Dec 12, 2025

This Cross-Site Scripting (XSS) vulnerability in Masa CMS allows attackers to inject malicious scripts via the ajax URL query parameter. When exploited, these scripts execute in users' browsers, poten...

CVE-2024-32642

HIGH CVSS 8.8 Dec 3, 2025

Masa CMS versions before 7.2.8, 7.3.13, and 7.4.6 are vulnerable to host header poisoning, which allows attackers to hijack password reset emails and take over user accounts. This affects all Masa CMS...

CVE-2024-32643

HIGH CVSS 7.5 Dec 3, 2025

Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 contain an authorization bypass vulnerability. By appending '/tag/' to page URLs, attackers can access restricted content without proper permissions...

CVE-2021-42183

HIGH CVSS 7.5 May 5, 2022

MasaCMS 7.2.1 contains a path traversal vulnerability in the image asset API endpoint that allows attackers to read arbitrary files from the server filesystem. This affects all MasaCMS 7.2.1 installat...