📦 Mccms

by Chshcms

🔍 What is Mccms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-26781

CRITICAL CVSS 9.8 Apr 28, 2023

CVE-2023-26781 is a critical SQL injection vulnerability in mccms 2.6 that allows remote attackers to execute arbitrary SQL commands through the Author Center's Reader Comments Search feature. This af...

CVE-2023-29815

HIGH CVSS 8.8 Apr 28, 2023

MCCMS v2.6.3 is vulnerable to Cross-Site Request Forgery (CSRF), allowing attackers to trick authenticated users into performing unintended actions on the CMS. This affects all users running the vulne...

CVE-2025-50234

MEDIUM CVSS 6.5 Aug 6, 2025

MCCMS v2.7.0 has a server-side request forgery (SSRF) vulnerability that allows attackers to make the application send requests to internal systems and read local files. This can lead to sensitive dat...

CVE-2025-51651

MEDIUM CVSS 5.5 Jul 14, 2025

An authenticated arbitrary file download vulnerability in Mccms v2.7.0 allows attackers with admin access to download any file from the server via a crafted GET request to /admin/Backups.php. This aff...

CVE-2025-5327

MEDIUM CVSS 6.3 May 29, 2025

This critical SSRF vulnerability in chshcms mccms 2.7 allows attackers to manipulate the 'pic' parameter to make the server send unauthorized requests to internal or external systems. It affects all i...