Myucms Project develops a content management system where the observable vulnerability signal centers on server-side code-injection and request-forgery weaknesses, reflecting risks in template rendering and HTTP client functionality. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myucms Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21652CRITICAL Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method. | Oct 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-21651CRITICAL Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method. | Oct 6, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-21653CRITICAL Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sj() method. | Oct 6, 2021 | 9.1 | 28 | NO | NO |
CVE-2020-21649HIGH Myucms v2.2.1 contains a server-side request forgery (SSRF) in the component \controller\index.php, which can be exploited via the sql() method. | Oct 6, 2021 | 8.1 | 25 | NO | NO |
CVE-2020-21650HIGH Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method. | Oct 6, 2021 | 8.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myucms Project.
Media articles that mention a CVE ID that affects a product developed by Myucms Project — matched by CVE ID, not by vendor name.