sitemagic CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

sitemagic vulnerability overview

Aggregates CVE and security vulnerability intelligence across all sitemagic-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk cross-site scripting and vendor risk csrf, with potential vendor impact session compromise across vendor surface production workloads and vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-53921 SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands. [email protected] 8.7 0.46% 2025-12-17 2025-12-31
CVE-2019-18220 Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions. [email protected] 8.8 0.47% 2019-10-23 2024-11-21
CVE-2019-18219 Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter. [email protected] 6.1 0.24% 2019-10-23 2024-11-21
CVE-2019-10238 Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter. [email protected] 6.1 0.24% 2019-03-27 2024-11-21
CVE-2019-9042 An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can only occur if the administrator neglects to set FileExtensionFilter and there are untrusted user accounts. NOTE: The maintainer states that this is not a vulnerability but a feature used in conjunction with External Modules [email protected] 7.2 0.94% 2019-02-23 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence