Sscms operates a content-management system whose vulnerability footprint clusters around a narrowly scoped product line, SiteServer CMS and its variants, with recurring exposure through application-layer input-handling issues including cross-site scripting, SQL injection, path traversal, and improper access control. Vulnerabilities affecting this vendor tend to reach serious outcomes, with a meaningful share advancing to critical severity. Defenders should treat updates for this CMS platform as a priority within affected deployments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sscms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42654CRITICAL SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code. | May 24, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-28118CRITICAL SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in. | May 3, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-44298CRITICAL SiteServer CMS 7.1.3 is vulnerable to SQL Injection. | Jan 27, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-44297CRITICAL SiteServer CMS 7.1.3 has a SQL injection vulnerability the background. | Jan 26, 2023 | 9.8 | 29 | NO | NO |
CVE-2021-42655HIGH SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability. | May 24, 2022 | 8.8 | 28 | NO | NO |
CVE-2025-52237MEDIUM An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory traversal. | Aug 5, 2025 | 6.5 | 25 | NO | NO |
CVE-2022-30349MEDIUM siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS). | Jun 2, 2022 | 6.1 | 22 | NO | NO |
CVE-2021-42656MEDIUM SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability. | May 24, 2022 | 5.4 | 21 | NO | NO |
CVE-2025-45529HIGH An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templat | May 27, 2025 | 7.1 | 20 | NO | NO |
CVE-2023-43952MEDIUM SSCMS 7.2.2 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Material Management component. | Oct 3, 2023 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sscms.
Media articles that mention a CVE ID that affects a product developed by Sscms — matched by CVE ID, not by vendor name.