74cms CVE Vulnerabilities & Metrics

Focus on 74cms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About 74cms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with 74cms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total 74cms CVEs: 33
Earliest CVE date: 25 Dec 2018, 17:29 UTC
Latest CVE date: 17 Oct 2022, 14:15 UTC

Latest CVE reference: CVE-2022-42154

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical 74cms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.05

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 22
7.0-8.9 8
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS 74cms CVEs

These are the five CVEs with the highest CVSS scores for 74cms, sorted by severity first and recency.

All CVEs for 74cms

CVE-2022-42154 74cms vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

An arbitrary file upload vulnerability in the component /apiadmin/upload/attach of 74cmsSE v3.13.0 allows attackers to execute arbitrary code via a crafted PHP file.

CVE-2022-41472 74cms vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

74cmsSE v3.12.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /apiadmin/notice/add. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Title field.

CVE-2022-41471 74cms vulnerability CVSS: 0 17 Oct 2022, 14:15 UTC

74cmsSE v3.12.0 allows authenticated attackers with low-level privileges to arbitrarily change the rights and credentials of the Super Administrator account.

CVE-2022-33097 74cms vulnerability CVSS: 5.0 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/campus/campus_job.

CVE-2022-33096 74cms vulnerability CVSS: 5.0 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/resume/index.

CVE-2022-33095 74cms vulnerability CVSS: 5.0 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

CVE-2022-33094 74cms vulnerability CVSS: 5.0 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/map.

CVE-2022-33093 74cms vulnerability CVSS: 5.0 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the key parameter at /freelance/resume_list.

CVE-2022-33092 74cms vulnerability CVSS: 5.0 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/job/index.

CVE-2022-32131 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /index/notice/show.

CVE-2022-32130 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/down_resume/total/nature.

CVE-2022-32129 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/account/safety/trade.

CVE-2022-32128 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/service/increment/add/im.

CVE-2022-32127 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company/view_be_browsed/total.

CVE-2022-32126 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /company.

CVE-2022-32125 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.

CVE-2022-32124 74cms vulnerability CVSS: 4.3 23 Jun 2022, 17:15 UTC

74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the component /index/jobfairol/show/.

CVE-2022-29721 74cms vulnerability CVSS: 5.0 26 May 2022, 13:15 UTC

74cmsSE v3.5.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /home/jobfairol/resumelist.

CVE-2022-29720 74cms vulnerability CVSS: 5.0 26 May 2022, 13:15 UTC

74cmsSE v3.5.1 was discovered to contain an arbitrary file read vulnerability via the component \index\controller\Download.php.

CVE-2022-26271 74cms vulnerability CVSS: 5.0 28 Mar 2022, 01:15 UTC

74cmsSE v3.4.1 was discovered to contain an arbitrary file read vulnerability via the $url parameter at \index\controller\Download.php.

CVE-2020-22421 74cms vulnerability CVSS: 4.3 08 Dec 2021, 04:15 UTC

74CMS v6.0.4 was discovered to contain a cross-site scripting (XSS) vulnerability via /index.php?m=&c=help&a=help_list&key.

CVE-2020-22212 74cms vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in 74cms 3.2.0 via the id parameter to wap/wap-company-show.php.

CVE-2020-22211 74cms vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in 74cms 3.2.0 via the key parameter to plus/ajax_street.php.

CVE-2020-22210 74cms vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in 74cms 3.2.0 via the x parameter to ajax_officebuilding.php.

CVE-2020-22209 74cms vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in 74cms 3.2.0 via the query parameter to plus/ajax_common.php.

CVE-2020-22208 74cms vulnerability CVSS: 7.5 16 Jun 2021, 18:15 UTC

SQL Injection in 74cms 3.2.0 via the x parameter to plus/ajax_street.php.

CVE-2020-35339 74cms vulnerability CVSS: 7.5 17 Feb 2021, 15:15 UTC

In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.

CVE-2020-29279 74cms vulnerability CVSS: 7.5 02 Dec 2020, 22:15 UTC

PHP remote file inclusion in the assign_resume_tpl method in Application/Common/Controller/BaseController.class.php in 74CMS before 6.0.48 allows remote code execution.

CVE-2019-17612 74cms vulnerability CVSS: 6.5 15 Oct 2019, 23:15 UTC

An issue was discovered in 74CMS v5.2.8. There is a SQL Injection generated by the _list method in the Common/Controller/BackendController.class.php file via the index.php?m=Admin&c=Ad&a=category sort parameter.

CVE-2019-11374 74cms vulnerability CVSS: 6.8 20 Apr 2019, 15:29 UTC

74CMS v5.0.1 has a CSRF vulnerability to add a new admin user via the index.php?m=Admin&c=admin&a=add URI.

CVE-2019-10684 74cms vulnerability CVSS: 7.5 01 Apr 2019, 16:29 UTC

Application/Admin/Controller/ConfigController.class.php in 74cms v5.0.1 allows remote attackers to execute arbitrary PHP code via the index.php?m=Admin&c=config&a=edit site_domain parameter.

CVE-2018-20519 74cms vulnerability CVSS: 5.5 27 Dec 2018, 15:29 UTC

An issue was discovered in 74cms v4.2.111. It allows remote authenticated users to read or modify arbitrary resumes by changing a job-search intention, as demonstrated by the index.php?c=Personal&a=ajax_save_basic pid parameter.

CVE-2018-20454 74cms vulnerability CVSS: 4.3 25 Dec 2018, 17:29 UTC

An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter.