Siteserver Cms

Vendor:

First CVE: May 3, 2022 · Active for 4 years

10
Total CVEs
More Total CVEs than 88% of tracked products
3.3
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 63% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Siteserver Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 3, 2022
4 years ago
Most Recent CVE
May 27, 2025
423 days ago

CVE Severity & Scoring

Siteserver Cms10 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network10 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low10 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (70.0%)
Unknown0 (0.0%)
Required3 (30.0%)
Privileges Required
Low3 (30.0%)
High1 (10.0%)
None6 (60.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SiteServer CMS < V5.1 is affected by an unrestricted upload of a file with dangerous type (getshell), which could be used to execute arbitrary code.
May 24, 20229.832NONO
SiteServer CMS v7.x allows attackers to execute arbitrary code via a crafted plug-in.
May 3, 20229.832NONO
SiteServer CMS 7.1.3 is vulnerable to SQL Injection.
Jan 27, 20239.830NONO
SiteServer CMS 7.1.3 has a SQL injection vulnerability the background.
Jan 26, 20239.829NONO
SiteServer CMS V6.15.51 is affected by a SQL injection vulnerability.
May 24, 20228.828NONO
siteserver SSCMS 6.15.51 is vulnerable to Cross Site Scripting (XSS).
Jun 2, 20226.122NONO
SiteServer CMS V6.15.51 is affected by a Cross Site Scripting (XSS) vulnerability.
May 24, 20225.421NONO
An arbitrary file read vulnerability in the ReadTextAsynchronous function of SSCMS v7.3.1 allows attackers to read arbitrary files via sending a crafted GET request to /cms/templat
May 27, 20257.120NONO
A vulnerability, which was classified as problematic, was found in SiteServer CMS up to 7.2.1. Affected is an unknown function of the file /api/stl/actions/search. The manipulation
May 24, 20236.117NONO
SiteServerCMS 7.1.3 sscms has a file read vulnerability.
Feb 16, 20234.915NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Siteserver Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.3.117.10.3%00
7.1.338.20.9%00
6.15.5136.80.8%00