ZeroHour

Vulnerabilities

53 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-51818
MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component.

MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

NVD description · AI analysis pending
5.4<1% PoC
  • chshcms mccms
CVE-2025-50234
MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed.

MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded key Mc_Encryption_Key (bD2voYwPpNuJ7B8), defined in the db.php file. The decrypted URL is passed to the geturl() method, which uses cURL to make a request to the URL without proper security checks. An attacker can craft a malicious encrypted pic parameter, which, when decrypted, points to internal addresses or local file paths (such as http://127.0.0.1 or file://). By using the file:// protocol, the attacker can access arbitrary files on the local file system (e.g., file:///etc/passwd, file:///C:/Windows/System32/drivers/etc/hosts), allowing them to read sensitive configuration files, log files, and more, leading to information leakage or system exposure. The danger of this SSRF vulnerability includes accessing internal services and local file systems through protocols like http://, ftp://, and file://, which can result in sensitive data leakage, remote code execution, privilege escalation, or full system compromise, severely affecting the system's security and stability.

NVD description · AI analysis pending
6.5<1% PoC
  • chshcms mccms
CVE-2025-51651
An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a cr

An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

NVD description · AI analysis pending
5.5<1% PoC
  • chshcms mccms
CVE-2025-5328
+1 in the same advisory: …5327
A vulnerability was found in chshcms mccms 2.7.

A vulnerability was found in chshcms mccms 2.7. It has been declared as critical. This vulnerability affects the function restore_del of the file /sys/apps/controllers/admin/Backups.php. The manipulation of the argument dirs leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.31% PoC
  • chshcms mccms
CVE-2023-5029
A vulnerability, which was classified as critical, was found in mccms 2.6.

A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871.

NVD description · AI analysis pending
8.8<1% PoC
  • chshcms mccms
CVE-2023-3236
+1 in the same advisory: …3235
A vulnerability classified as critical has been found in mccms up to 2.6.5.

A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231507.

NVD description · AI analysis pending
8.8<1% PoC
  • chshcms mccms
CVE-2023-26781
+2 in the same advisory: …29815 …26782
SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

NVD description · AI analysis pending
9.8
group max
<1% PoC
  • chshcms mccms
CVE-2022-30898
A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.

A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.

NVD description · AI analysis pending
6.5<1% PoC
  • chshcms cscms
CVE-2022-29660
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

NVD description · AI analysis pending
9.8
group max
12% PoC
  • chshcms cscms music portal system
CVE-2022-28552
Cscms 4.1 is vulnerable to SQL Injection.

Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

NVD description · AI analysis pending
8.8<1% PoC
  • chshcms cscms
CVE-2022-27365
+4 in the same advisory: …27369 …27368 …27367 …27366
Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.

Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.

NVD description · AI analysis pending
7.2<1% PoC
  • chshcms cscms
CVE-2022-27090
Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.

Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • chshcms cscms
CVE-2020-28102
+1 in the same advisory: …28103
cscms v4.1 allows for SQL injection via the "js_del" function.

cscms v4.1 allows for SQL injection via the "js_del" function.

NVD description · AI analysis pending
9.81% PoC
  • chshcms cscms
CVE-2020-21238
An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.

An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.

NVD description · AI analysis pending
9.8<1% PoC
  • chshcms cscms
CVE-2020-22848
A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.

A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.

NVD description · AI analysis pending
9.83% PoC
  • chshcms cscms
CVE-2019-9598
An issue was discovered in Cscms 4.1.0.

An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.

NVD description · AI analysis pending
6.5<1% PoC
  • chshcms cscms
CVE-2019-6779
Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.

Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.

NVD description · AI analysis pending
8.1<1% PoC
  • chshcms cscms
CVE-2018-17126
+1 in the same advisory: …17125
CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.

CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.

NVD description · AI analysis pending
9.8
group max
3% PoC ×2
  • chshcms cscms
CVE-2018-16731
+1 in the same advisory: …16732
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathnam

CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • chshcms cscms