Mura Cms
Vendor:
First CVE: Feb 1, 2023 · Active for 3 years
9
Total CVEs
More Total CVEs than 88% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
8.5
Avg CVSS
Higher Avg CVSS than 77% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mura Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 1, 2023
3 years ago
Most Recent CVE
Mar 18, 2026
131 days ago
CVE Severity & Scoring
Mura Cms9 CVEs
11%
56%
33%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low1 (11.1%)
High0 (0.0%)
None8 (88.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47003CRITICAL A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request. | Feb 1, 2023 | 9.8 | 46 | NO | YES |
CVE-2025-67830CRITICAL Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. | Mar 18, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-67829CRITICAL Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. | Mar 18, 2026 | 9.8 | 29 | NO | NO |
CVE-2025-55040HIGH The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions through a CSRF attack. The vulnerable cForm.importfo | Mar 18, 2026 | 8.8 | 27 | NO | NO |
CVE-2025-55044HIGH The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unauthorized locations through CSRF. The vulnerable cT | Mar 18, 2026 | 8.8 | 25 | NO | NO |
CVE-2025-55046HIGH MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in the trash system through a simple CSRF attack. The | Mar 18, 2026 | 8.1 | 23 | NO | NO |
CVE-2025-55041HIGH MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup method) that allows attackers to escalate privile | Mar 18, 2026 | 8.0 | 23 | NO | NO |
CVE-2025-55045HIGH The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through CSRF. The vulnerable cUsers.updateAddress function | Mar 18, 2026 | 7.1 | 21 | NO | NO |
CVE-2025-55043MEDIUM MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) that allows unauthenticated attackers to force admini | Mar 18, 2026 | 6.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
11.1% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Mura Cms
Top CWEs
Versions
No cataloged versions.