Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Murasoftware

First CVE: Feb 1, 2023Active for: 3 yearsTotal CVEs: 9

Murasoftware's vulnerability profile centers on Mura CMS, a web content management system whose disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code. The recurring weakness classes—cross-site request forgery, SQL injection, and improper authentication—reflect the input-handling and access-control demands of a web-facing application platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
8.5
Avg CVSS Score
Higher Avg CVSS Score than 82% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Murasoftware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2023
3 years ago
Most Recent CVE
Mar 18, 2026
128 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-47003CRITICAL
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
Feb 1, 20239.846NOYES
CVE-2025-67830CRITICAL
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
Mar 18, 20269.829NONO
CVE-2025-67829CRITICAL
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
Mar 18, 20269.829NONO
CVE-2025-55040HIGH
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importfo
Mar 18, 20268.827NONO
CVE-2025-55044HIGH
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cT
Mar 18, 20268.825NONO
CVE-2025-55046HIGH
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The
Mar 18, 20268.123NONO
CVE-2025-55041HIGH
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privile
Mar 18, 20268.023NONO
CVE-2025-55045HIGH
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function
Mar 18, 20267.121NONO
CVE-2025-55043MEDIUM
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force admini
Mar 18, 20266.520NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
11%
56%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Murasoftware.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Murasoftware — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Murasoftware's Products

View all 1 CNAs →

Top CWEs