Sitemagic develops a content management system (Sitemagic CMS) whose vulnerability profile centers on web application input-handling and file-management weaknesses, including cross-site scripting, unrestricted file upload, and cross-site request forgery. The observed exposure reflects typical risks in web-facing CMS platforms where user input and file-upload boundaries require careful validation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sitemagic over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53921CRITICAL SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar fi | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2019-18220HIGH Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical fu | Oct 23, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-9042HIGH An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can o | Feb 23, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-10238MEDIUM Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter. | Mar 27, 2019 | 6.1 | 21 | NO | NO |
CVE-2019-18219MEDIUM Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaSc | Oct 23, 2019 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sitemagic.
Media articles that mention a CVE ID that affects a product developed by Sitemagic — matched by CVE ID, not by vendor name.