Skip to main content

Vendor/product archive

mara_cms_project / mara_cms CVEs

Beta · best-effort

3 CVEs tagged to mara_cms_project / mara_cms1 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2021-36547

Published Oct 28, 2021

A remote code execution (RCE) vulnerability in the component /codebase/dir.php?type=filenew of Mara v7.5 allows attackers to execute arbitrary commands via a crafted PHP file.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-25422

Published Oct 28, 2021

A cross site scripting (XSS) vulnerability in menuedit.php of Mara CMS 7.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1