Murasoftware's vulnerability profile centers on Mura CMS, a web content management system whose disclosures skew strongly toward critical-severity outcomes and frequently acquire public exploit code. The recurring weakness classes—cross-site request forgery, SQL injection, and improper authentication—reflect the input-handling and access-control demands of a web-facing application platform. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Murasoftware over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47003CRITICAL A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. | Feb 1, 2023 | 9.8 | 46 | NO | YES |
CVE-2025-67830CRITICAL Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. | Mar 18, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-67829CRITICAL Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. | Mar 18, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-55040HIGH The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importfo | Mar 18, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-55044HIGH The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cT | Mar 18, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-55046HIGH MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The | Mar 18, 2026 | 8.1 | 23 | NO | NO |
CVE-2025-55041HIGH MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privile | Mar 18, 2026 | 8.0 | 23 | NO | NO |
CVE-2025-55045HIGH The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function | Mar 18, 2026 | 7.1 | 21 | NO | NO |
CVE-2025-55043MEDIUM MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force admini | Mar 18, 2026 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Murasoftware.
Media articles that mention a CVE ID that affects a product developed by Murasoftware — matched by CVE ID, not by vendor name.