S CMS is a content management system that occupies a niche but prominent position in the vulnerability landscape, with its disclosures concentrated in the product itself and its enterprise website construction variant. The vendor's vulnerability footprint remains modest in absolute terms while commanding attention within its application category, driven by the web-facing nature and user-administration scope of CMS platforms. Specific weakness patterns have not yet coalesced into a durable recurring profile across its disclosures, and defenders should monitor emerging update advisories to establish mitigation cadence as the product's threat model clarifies. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by S Cms over time
Signals from CVEs in this vendor scope (42 CVEs).
42 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10708CRITICAL S-CMS PHP v1.0 has SQL injection via the 4/js/scms.php?action=unlike id parameter. | Apr 2, 2019 | 9.8 | 32 | NO | NO |
CVE-2021-37270CRITICAL There is an unauthorized access vulnerability in the CMS Enterprise Website Construction System 5.0. Attackers can use this vulnerability to directly access the specified backgroun | Sep 27, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-20480CRITICAL An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter. | Dec 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-20477CRITICAL An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field. | Dec 26, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-18887CRITICAL S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field). | Nov 1, 2018 | 9.8 | 31 | NO | NO |
CVE-2022-23336CRITICAL S-CMS v5.0 was discovered to contain a SQL injection vulnerability in member_pay.php via the O_id parameter. | Feb 14, 2022 | 9.8 | 30 | NO | NO |
CVE-2019-6805CRITICAL SQL Injection was found in S-CMS version V3.0 via the alipay/alipayapi.php O_id parameter. | Jan 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2023-51049CRITICAL S-CMS v5.0 was discovered to contain a SQL injection vulnerability via the A_bbsauth parameter at /admin/ajax.php. | Dec 21, 2023 | 9.8 | 29 | NO | NO |
CVE-2018-20479CRITICAL An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter. | Dec 26, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-18427CRITICAL s-cms 3.0 allows SQL Injection via the member/post.php 0_id parameter or the POST data to member/member_login.php. | Oct 17, 2018 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (42 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by S Cms.
Media articles that mention a CVE ID that affects a product developed by S Cms — matched by CVE ID, not by vendor name.