Magnolia CMS is a Java-based content management system with a modestly represented vulnerability footprint concentrated in its core product and form-handling module. The recurring disclosures center on input-validation and authentication weaknesses characteristic of web-facing CMS platforms. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Magnolia Cms over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33098MEDIUM Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary we | Jul 7, 2022 | 6.1 | 56 | NO | YES |
CVE-2021-46362CRITICAL A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a | Feb 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2021-46361CRITICAL An issue in the Freemark Filter of Magnolia CMS v6.2.11 and below allows attackers to bypass security restrictions and execute arbitrary code via a crafted FreeMarker payload. | Feb 11, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-46366HIGH An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute | Feb 11, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-46363HIGH An issue in the Export function of Magnolia v6.2.3 and below allows attackers to perform Formula Injection attacks via crafted CSV/XLS files. These formulas may result in arbitrary | Feb 11, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-46365HIGH An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file. | Feb 11, 2022 | 7.8 | 25 | NO | NO |
CVE-2013-4759MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary we | Aug 9, 2013 | 4.3 | 22 | NO | YES |
CVE-2021-25894MEDIUM Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the /magnoliaPublic/travel/members/login.html mgnlUserId parameter. | Apr 2, 2021 | 6.1 | 21 | NO | NO |
CVE-2021-46364HIGH A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file. | Feb 11, 2022 | 7.8 | 20 | NO | NO |
CVE-2021-25893MEDIUM Magnolia CMS from 6.1.3 to 6.2.3 contains a stored cross-site scripting (XSS) vulnerability in the setText parameter of /magnoliaAuthor/.magnolia/. | Apr 2, 2021 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Magnolia Cms.
Media articles that mention a CVE ID that affects a product developed by Magnolia Cms — matched by CVE ID, not by vendor name.