Chshcms develops a narrow portfolio of content management and music portal systems that, despite a small product line, occupy a notable position in the landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity. The exposure recurs consistently across products such as CSCMS and the Music Portal System through a cluster of input-handling and access-control weakness classes: SQL injection, cross-site request forgery, server-side request forgery, code injection, and path traversal, reflecting the web-application and file-access demands of content management platforms. Defenders should treat this vendor's advisory activity seriously and prioritize patching for internet-exposed instances; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Chshcms over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-29660CRITICAL CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | May 26, 2022 | 9.8 | 36 | NO | NO |
CVE-2018-16731CRITICAL CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSO | Sep 8, 2018 | 9.8 | 32 | NO | NO |
CVE-2020-21238CRITICAL An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks. | Dec 27, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-22848CRITICAL A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands. | Aug 30, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-17126CRITICAL CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php. | Sep 17, 2018 | 9.8 | 30 | NO | NO |
CVE-2023-3236HIGH A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of | Jun 14, 2023 | 8.8 | 28 | NO | NO |
CVE-2023-26781CRITICAL SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search. | Apr 28, 2023 | 9.8 | 28 | NO | NO |
CVE-2022-29669HIGH CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan. | May 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-29667HIGH CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos | May 26, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-29664HIGH CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save. | May 26, 2022 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Chshcms.
Media articles that mention a CVE ID that affects a product developed by Chshcms — matched by CVE ID, not by vendor name.