Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Masacms

First CVE: May 5, 2022Active for: 4 yearsTotal CVEs: 6

Masacms is a content management system whose vulnerability profile is concentrated in its core product and skews strongly toward critical-severity outcomes. The recurring exposure centers on web-application control and input-handling weaknesses—including improper authorization, code injection, path traversal, cross-site scripting, and origin validation flaws—that are typical of CMS platforms handling untrusted user input and file operations, and public exploit code for these classes tends to be available. Defenders tracking this vendor should prioritize patching of its releases and monitor for misconfigurations that expose administrative functionality; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Masacms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 5, 2022
4 years ago
Most Recent CVE
Dec 12, 2025
224 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-47002CRITICAL
A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.
Feb 1, 20239.845NOYES
CVE-2024-32641CRITICAL
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability ex
Dec 3, 20259.841NONO
CVE-2021-42183HIGH
MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/.
May 5, 20227.526NONO
CVE-2024-32643HIGH
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS wil
Dec 3, 20257.525NONO
CVE-2024-32642HIGH
Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via
Dec 3, 20258.825NONO
CVE-2025-66492MEDIUM
Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerabl
Dec 12, 20256.122NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
50%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
16.7% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Masacms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Masacms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Masacms's Products

View all 2 CNAs →

Top CWEs