Motocms is a website builder platform with a narrow product footprint centered on its core content-management offering. Its observed vulnerability profile clusters around output-encoding and database-query construction issues, including injection and SQL-injection weaknesses that are characteristic of web-application input handling.
The number and severity of CVEs published that impact products developed by Motocms over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-36210CRITICAL MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter. | Aug 1, 2023 | 9.8 | 41 | NO | NO |
CVE-2023-36213CRITICAL SQL injection vulnerability in MotoCMS v.3.4.3 allows a remote attacker to gain privileges via the keyword parameter of the search function. | Aug 3, 2023 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Motocms.
Media articles that mention a CVE ID that affects a product developed by Motocms — matched by CVE ID, not by vendor name.