Macs Cms Project is a narrowly scoped content management system vendor whose vulnerability record concentrates in its eponymous Macs CMS product and is characterized by recurrent web-application input-handling weaknesses, including SQL injection, cross-site scripting, and type-confusion issues. These are representative of server-side and client-side validation gaps in web-facing applications; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Macs Cms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-43154CRITICAL In Macrob7 Macs Framework Content Management System (CMS) 1.1.4f, loose comparison in "isValidLogin()" function during login attempt results in PHP type confusion vulnerability tha | Sep 27, 2023 | 9.8 | 27 | NO | NO |
CVE-2020-23045HIGH Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a SQL injection vulnerability via the 'roleId' parameter of the `editRole` and `deletUser` module | Oct 22, 2021 | 7.2 | 23 | NO | NO |
CVE-2020-23047MEDIUM Macrob7 Macs Framework Content Management System - 1.14f was discovered to contain a cross-site scripting (XSS) vulnerability in the search input field of the search module. | Oct 22, 2021 | 6.1 | 21 | NO | NO |
CVE-2023-45503MEDIUM SQL Injection vulnerability in Macrob7 Macs CMS 1.1.4f, allows remote attackers to execute arbitrary code, cause a denial of service (DoS), escalate privileges, and obtain sensitiv | Apr 15, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Macs Cms Project.
Media articles that mention a CVE ID that affects a product developed by Macs Cms Project — matched by CVE ID, not by vendor name.