Mtcms is a content management system product with a niche vulnerability footprint centered on application-layer input handling and data-access weaknesses, including cross-site scripting, SQL injection, and related input-validation flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mtcms over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0280HIGH SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via the (1) a or (2) cid parameter. | Jan 15, 2008 | 7.5 | 30 | NO | YES |
CVE-2006-6796MEDIUM PHP remote file inclusion vulnerability in admin/admin_settings.php in MTCMS 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ins_file paramet | Dec 28, 2006 | 6.8 | 27 | NO | YES |
CVE-2007-1129HIGH Multiple unrestricted file upload vulnerabilities in MTCMS 3.2 allow remote attackers to upload and execute files via (1) an avatar upload in an add_down action, or (2) an add_link | Feb 27, 2007 | 7.5 | 19 | NO | NO |
CVE-2007-1132MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the "Contact Us" functionality in MTCMS 2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) message | Feb 27, 2007 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mtcms.
Media articles that mention a CVE ID that affects a product developed by Mtcms — matched by CVE ID, not by vendor name.