Skip to main content

Vendor archive

sscms CVEs

Beta · best-effort

12 CVEs tagged to vendor sscms4 Critical, 2 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2025-52237

Published Aug 5, 2025

An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-45529

Published May 27, 2025

An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templa…

CVSS 7.1 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2023-43953

Published Oct 3, 2023

SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-2862

Published May 24, 2023

A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulatio…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2021-42654

Published May 24, 2022

SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-28118

Published May 3, 2022

SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1