Masacms is a content management system whose vulnerability profile is concentrated in its core product and skews strongly toward critical-severity outcomes. The recurring exposure centers on web-application control and input-handling weaknesses—including improper authorization, code injection, path traversal, cross-site scripting, and origin validation flaws—that are typical of CMS platforms handling untrusted user input and file operations, and public exploit code for these classes tends to be available. Defenders tracking this vendor should prioritize patching of its releases and monitor for misconfigurations that expose administrative functionality; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Masacms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47002CRITICAL A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request. | Feb 1, 2023 | 9.8 | 45 | NO | YES |
CVE-2024-32641CRITICAL Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability ex | Dec 3, 2025 | 9.8 | 41 | NO | NO |
CVE-2021-42183HIGH MasaCMS 7.2.1 is affected by a path traversal vulnerability in /index.cfm/_api/asset/image/. | May 5, 2022 | 7.5 | 26 | NO | NO |
CVE-2024-32643HIGH Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, if the URL to the page is modified to include a /tag/ declaration, the CMS wil | Dec 3, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-32642HIGH Masa CMS is an open source Enterprise Content Management platform. Prior to 7.2.8, 7.3.13, and 7.4.6, there is vulnerable to host header poisoning which allows account takeover via | Dec 3, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-66492MEDIUM Masa CMS is an open source Enterprise Content Management platform. Versions 7.2.8 and below, 7.3.1 through 7.3.13, 7.4.0-alpha.1 through 7.4.8 and 7.5.0 through 7.5.1 are vulnerabl | Dec 12, 2025 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Masacms.
Media articles that mention a CVE ID that affects a product developed by Masacms — matched by CVE ID, not by vendor name.