Products: 3
    Vulnerabilities: 53
    Known Exploited: 0
    8
    Critical Level Threats
    31
    High Level Threats
    14
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2025-51818

    MCCMS 2.7.0 is vulnerable to Arbitrary file deletion in the Backups.php component. This allows an attacker to execute arbitrary commands

    Last Modified: Sep 24, 2025
    Published: Aug 21, 2025

    CVE-2025-50234

    MCCMS v2.7.0 has an SSRF vulnerability located in the index() method of the sys\apps\controllers\api\Gf.php file, where the pic parameter is processed. The pic parameter is decrypted using the sys_auth($pic, 1) function, which utilizes a hard-coded key Mc_Encryption_Key (bD2voYwPpNuJ7B8), defined in the db.php file. The decrypted URL is passed to the geturl() method, which uses cURL to make a request to the URL without proper security checks. An attacker can craft a malicious encrypted pic parameter, which, when decrypted, points to internal addresses or local file paths (such as http://127.0.0.1 or file://). By using the file:// protocol, the attacker can access arbitrary files on the local file system (e.g., file:///etc/passwd, file:///C:/Windows/System32/drivers/etc/hosts), allowing them to read sensitive configuration files, log files, and more, leading to information leakage or system exposure. The danger of this SSRF vulnerability includes accessing internal services and local file systems through protocols like http://, ftp://, and file://, which can result in sensitive data leakage, remote code execution, privilege escalation, or full system compromise, severely affecting the system's security and stability.

    Last Modified: Aug 18, 2025
    Published: Aug 06, 2025

    CVE-2025-51651

    An authenticated arbitrary file download vulnerability in the component /admin/Backups.php of Mccms v2.7.0 allows attackers to download arbitrary files via a crafted GET request.

    Last Modified: Jul 17, 2025
    Published: Jul 14, 2025

    CVE-2025-5328

    chshcms mccms Backups.php restore_del path traversal

    Last Modified: Jun 10, 2025
    Published: May 29, 2025

    CVE-2025-5327

    chshcms mccms Gf.php index server-side request forgery

    Last Modified: Jun 10, 2025
    Published: May 29, 2025
    Items Per Page
    Chshcms Vulnerabilities & Security CVEs | CVE-DB