ZeroHour

Vulnerabilities

37 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-10395
+1 in the same advisory: …10397
A vulnerability was found in Magicblack MacCMS 2025.1000.4050.

A vulnerability was found in Magicblack MacCMS 2025.1000.4050. Affected by this vulnerability is the function col_url of the component Scheduled Task Handler. Performing manipulation of the argument cjurl results in server-side request forgery. It is possible to initiate the attack remotely.

NVD description · AI analysis pending
5.1
group max
<1%
  • maccms maccms
CVE-2025-10122
A vulnerability was found in Maccms10 2025.1000.4050.

A vulnerability was found in Maccms10 2025.1000.4050. Affected is the function rep of the file application/admin/controller/Database.php. Performing manipulation of the argument where results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

NVD description · AI analysis pending
2.0<1%
  • maccms maccms
CVE-2025-45474
maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

maccms10 v2025.1000.4047 is vulnerable to Server-side request forgery (SSRF) in Email Settings.

NVD description · AI analysis pending
7.3<1% PoC
  • maccms maccms
CVE-2025-45475
maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

maccms10 v2025.1000.4047 is vulnerable to Server-Side request forgery (SSRF) in Friend Link Management.

NVD description · AI analysis pending
5.4<1% PoC
  • maccms maccms
CVE-2025-28091
+2 in the same advisory: …28089 …28090
maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

maccms10 v2025.1000.4047 has a Server-Side Request Forgery (SSRF) vulnerability via Add Article.

NVD description · AI analysis pending
9.1<1% PoC
  • maccms maccms
CVE-2024-46654
A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts

A stored cross-site scripting (XSS) vulnerability in the Add Scheduled Task module of Maccms10 v2024.1000.4040 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

NVD description · AI analysis pending
4.8<1% PoC
  • maccms maccms
CVE-2024-32391
Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

Cross Site Scripting vulnerability in MacCMS v.10 v.2024.1000.3000 allows a remote attacker to execute arbitrary code via a crafted payload.

NVD description · AI analysis pending
7.3<1% PoC
  • maccms maccms
CVE-2022-47872
A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload inje

A Server-Side Request Forgery (SSRF) in maccms10 v2021.1000.2000 allows attackers to force the application to make arbitrary requests via a crafted payload injected into the Name parameter under the Interface address module.

NVD description · AI analysis pending
8.8<1% PoC
  • maccms maccms
CVE-2022-44870
A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload

A reflected cross-site scripting (XSS) vulnerability in maccms10 v2022.1000.3032 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter under the AD Management module.

NVD description · AI analysis pending
6.1<1% PoC ×2
  • maccms maccms
CVE-2022-35148
maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

maccms10 v2021.1000.1081 to v2022.1000.3031 was discovered to contain a SQL injection vulnerability via the table parameter at database/columns.html.

NVD description · AI analysis pending
6.5<1% PoC
  • maccms maccms
CVE-2022-31303
+1 in the same advisory: …31302
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.

NVD description · AI analysis pending
5.4<1% PoC
  • maccms maccms
CVE-2021-43707
Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

Cross Site Scripting (XSS) vulnerability exists in Maccms v10 via link_Name parameter.

NVD description · AI analysis pending
6.1<1% PoC
  • maccms maccms
CVE-2022-26573
+4 in the same advisory: …27886 …27885 …27884 …27887
Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input pa

Maccms v10 was discovered to contain multiple reflected cross-site scripting (XSS) vulnerabilities in /admin.php/admin/art/data.html via the select and input parameters.

NVD description · AI analysis pending
6.1<1% PoC
  • maccms maccms
CVE-2021-45786
+1 in the same advisory: …45787
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • maccms maccms
CVE-2020-21386
+2 in the same advisory: …21387 …21434
A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.

A Cross-Site Request Forgery (CSRF) in the component admin.php/admin/type/info.html of Maccms 10 allows attackers to gain administrator privileges.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • maccms maccms
CVE-2020-20514
A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/ .html allows authenticated attackers to delete all users.

A Cross-Site Request Forgery (CSRF) in Maccms v10 via admin.php/admin/admin/del/ids/ .html allows authenticated attackers to delete all users.

NVD description · AI analysis pending
8.1<1% PoC
  • maccms maccms
CVE-2020-21081
+1 in the same advisory: …21082
A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

A cross-site request forgery (CSRF) in Maccms 8.0 causes administrators to add and modify articles without their knowledge via clicking on a crafted URL.

NVD description · AI analysis pending
6.5
group max
<1% PoC
  • maccms maccms
CVE-2020-21359
+2 in the same advisory: …21363 …21362
An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrar

An arbitrary file upload vulnerability in the Template Upload function of Maccms10 allows attackers bypass the suffix whitelist verification to execute arbitrary code via adding a character to the end of the uploaded file's name.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • maccms maccms
CVE-2018-19465
Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related

Maccms through 8.0 allows XSS via the site_keywords field to index.php?m=system-config because of tpl/module/system.php and tpl/html/system_config.html, related to template/paody/html/vod_index.html.

NVD description · AI analysis pending
6.1<1% PoC
  • maccms maccms
CVE-2019-9829
Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action.

Maccms 10 allows remote attackers to execute arbitrary PHP code by entering this code in a template/default_pc/html/art Edit action. This occurs because template rendering uses an include operation on a cache file, which bypasses the prohibition of .php files as templates.

NVD description · AI analysis pending
8.82% PoC
  • maccms maccms
CVE-2019-8410
Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module

Maccms 8.0 allows XSS via the inc/config/cache.php t_key parameter because template/paody/html/vod_type.html mishandles the keywords parameter, and a/tpl/module/db.php only filters the t_name parameter (not t_key).

NVD description · AI analysis pending
6.1<1% PoC
  • maccms maccms
CVE-2018-12114
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.

NVD description · AI analysis pending
8.83% PoC ×3
  • maccms maccms
CVE-2017-17733
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.

NVD description · AI analysis pending
9.844% PoC
  • maccms maccms