Vulnerabilities
Vulnerable Software
Sscms:  Security Vulnerabilities
An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal.
CVSS Score
6.5
EPSS Score
0.005
Published
2025-08-05
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templates/templatesAssetsEditor.
CVSS Score
7.1
EPSS Score
0.003
Published
2025-05-27
SSCMS 7.2.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the Content Management component.
CVSS Score
5.4
EPSS Score
0.003
Published
2023-10-03
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation of the argument ajaxDivId leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. VDB-229818 is the identifier assigned to this vulnerability.
CVSS Score
3.5
EPSS Score
0.006
Published
2023-05-24
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
CVSS Score
4.9
EPSS Score
0.008
Published
2023-02-16
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-01-27
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
CVSS Score
9.8
EPSS Score
0.01
Published
2023-01-26
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
CVSS Score
6.1
EPSS Score
0.007
Published
2022-06-02
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.017
Published
2022-05-24
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
CVSS Score
8.8
EPSS Score
0.012
Published
2022-05-24


Contact Us

Shodan ® - All rights reserved