chshcms CVE Vulnerabilities & Metrics

Focus on chshcms vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About chshcms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with chshcms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total chshcms CVEs: 48
Earliest CVE date: 02 Sep 2018, 18:29 UTC
Latest CVE date: 17 Sep 2023, 22:15 UTC

Latest CVE reference: CVE-2023-5029

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical chshcms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.94

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 39
7.0-8.9 6
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS chshcms CVEs

These are the five CVEs with the highest CVSS scores for chshcms, sorted by severity first and recency.

All CVEs for chshcms

CVE-2023-5029 chshcms vulnerability CVSS: 5.2 17 Sep 2023, 22:15 UTC

A vulnerability, which was classified as critical, was found in mccms 2.6. This affects an unknown part of the file /category/order/hits/copyright/46/finish/1/list/1. The manipulation with the input '"1 leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-239871.

CVE-2023-3236 chshcms vulnerability CVSS: 6.5 14 Jun 2023, 07:15 UTC

A vulnerability classified as critical has been found in mccms up to 2.6.5. This affects the function pic_save of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument pic leads to server-side request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-231507.

CVE-2023-3235 chshcms vulnerability CVSS: 6.5 14 Jun 2023, 07:15 UTC

A vulnerability was found in mccms up to 2.6.5. It has been rated as critical. Affected by this issue is the function pic_api of the file sys/apps/controllers/admin/Comic.php. The manipulation of the argument url leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-231506 is the identifier assigned to this vulnerability.

CVE-2023-26782 chshcms vulnerability CVSS: 0 28 Apr 2023, 20:15 UTC

An issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System Configuration->Cache Configuration->Cache security characters.

CVE-2023-26781 chshcms vulnerability CVSS: 0 28 Apr 2023, 20:15 UTC

SQL injection vulnerability in mccms 2.6 allows remote attackers to run arbitrary SQL commands via Author Center ->Reader Comments ->Search.

CVE-2023-29815 chshcms vulnerability CVSS: 0 28 Apr 2023, 15:15 UTC

mccms v2.6.3 is vulnerable to Cross Site Request Forgery (CSRF).

CVE-2022-30898 chshcms vulnerability CVSS: 4.3 09 Jun 2022, 19:15 UTC

A Cross-site request forgery (CSRF) vulnerability in Cscms music portal system v4.2 allows remote attackers to change the administrator's username and password.

CVE-2022-29689 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.

CVE-2022-29688 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.

CVE-2022-29687 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.

CVE-2022-29686 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.

CVE-2022-29685 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.

CVE-2022-29684 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del.

CVE-2022-29683 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.

CVE-2022-29682 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.

CVE-2022-29681 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.

CVE-2022-29680 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.

CVE-2022-29676 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.

CVE-2022-29670 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.

CVE-2022-29669 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.

CVE-2022-29667 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.

CVE-2022-29666 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.

CVE-2022-29665 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save.

CVE-2022-29664 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save.

CVE-2022-29663 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy.

CVE-2022-29662 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save.

CVE-2022-29661 chshcms vulnerability CVSS: 6.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save.

CVE-2022-29660 chshcms vulnerability CVSS: 7.5 26 May 2022, 14:15 UTC

CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del.

CVE-2022-28552 chshcms vulnerability CVSS: 6.5 04 May 2022, 15:15 UTC

Cscms 4.1 is vulnerable to SQL Injection. Log into the background, open the song module, create a new song, delete it to the recycle bin, and SQL injection security problems will occur when emptying the recycle bin.

CVE-2022-27369 chshcms vulnerability CVSS: 6.5 15 Apr 2022, 18:15 UTC

Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component news_News.php_hy.

CVE-2022-27368 chshcms vulnerability CVSS: 6.5 15 Apr 2022, 18:15 UTC

Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Lists.php_zhuan.

CVE-2022-27367 chshcms vulnerability CVSS: 6.5 15 Apr 2022, 18:15 UTC

Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Topic.php_del.

CVE-2022-27366 chshcms vulnerability CVSS: 6.5 15 Apr 2022, 18:15 UTC

Cscms Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the component dance_Dance.php_hy.

CVE-2022-27365 chshcms vulnerability CVSS: 6.5 15 Apr 2022, 18:15 UTC

Cscms Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the component dance_Dance.php_del.

CVE-2022-27090 chshcms vulnerability CVSS: 4.9 21 Mar 2022, 22:15 UTC

Cscms Music Portal System v4.2 was discovered to contain a redirection vulnerability via the backurl parameter.

CVE-2020-28103 chshcms vulnerability CVSS: 7.5 11 Jan 2022, 16:15 UTC

cscms v4.1 allows for SQL injection via the "page_del" function.

CVE-2020-28102 chshcms vulnerability CVSS: 7.5 11 Jan 2022, 16:15 UTC

cscms v4.1 allows for SQL injection via the "js_del" function.

CVE-2020-21238 chshcms vulnerability CVSS: 5.0 27 Dec 2021, 23:15 UTC

An issue in the user login box of CSCMS v4.0 allows attackers to hijack user accounts via brute force attacks.

CVE-2020-22848 chshcms vulnerability CVSS: 7.5 30 Aug 2021, 23:15 UTC

A remote code execution (RCE) vulnerability in the \Playsong.php component of cscms v4.1 allows attackers to execute arbitrary commands.

CVE-2019-9598 chshcms vulnerability CVSS: 4.3 07 Mar 2019, 23:29 UTC

An issue was discovered in Cscms 4.1.0. There is an admin.php/pay CSRF vulnerability that can change the payment account to redirect funds.

CVE-2019-6779 chshcms vulnerability CVSS: 5.8 24 Jan 2019, 19:29 UTC

Cscms 4.1.8 allows admin.php/links/save CSRF to add, modify, or delete friend links.

CVE-2018-17126 chshcms vulnerability CVSS: 7.5 17 Sep 2018, 04:29 UTC

CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.

CVE-2018-17125 chshcms vulnerability CVSS: 6.4 17 Sep 2018, 04:29 UTC

CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php.

CVE-2018-16732 chshcms vulnerability CVSS: 6.8 08 Sep 2018, 15:29 UTC

\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.

CVE-2018-16731 chshcms vulnerability CVSS: 7.5 08 Sep 2018, 15:29 UTC

CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.

CVE-2018-16730 chshcms vulnerability CVSS: 4.3 08 Sep 2018, 15:29 UTC

\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.

CVE-2018-16448 chshcms vulnerability CVSS: 6.8 04 Sep 2018, 04:29 UTC

Cscms 4 allows CSRF for creating a member via upload/admin.php/user/save, authenticating vip members via upload/admin.php/user/init/tid and upload/admin.php/user/init/rzid, and creating a super administrator and web editor via upload/admin.php/sys/save.

CVE-2018-16337 chshcms vulnerability CVSS: 4.3 02 Sep 2018, 18:29 UTC

An issue was discovered in Cscms V4.1.8. There is a CSRF vulnerability that can modify a website's basic configuration via upload/admin.php/setting/save.