sitemagic CVE Vulnerabilities & Metrics

Focus on sitemagic vulnerabilities and metrics.

Last updated: 16 Jan 2026, 23:25 UTC

About sitemagic Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with sitemagic. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total sitemagic CVEs: 5
Earliest CVE date: 23 Feb 2019, 18:29 UTC
Latest CVE date: 17 Dec 2025, 23:15 UTC

Latest CVE reference: CVE-2023-53921

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 1

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical sitemagic CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.38

Max CVSS: 6.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 4
7.0-8.9 0
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS sitemagic CVEs

These are the five CVEs with the highest CVSS scores for sitemagic, sorted by severity first and recency.

All CVEs for sitemagic

CVE-2023-53921 sitemagic vulnerability CVSS: 0 17 Dec 2025, 23:15 UTC

SitemagicCMS 4.4.3 contains a remote code execution vulnerability that allows attackers to upload malicious PHP files to the files/images directory. Attackers can upload a .phar file with system command execution payload to compromise the web application and execute arbitrary system commands.

CVE-2019-18220 sitemagic vulnerability CVSS: 6.8 23 Oct 2019, 14:15 UTC

Sitemagic CMS 4.4.1 is affected by a Cross-Site-Request-Forgery (CSRF) issue as it doesn't implement any method to validate incoming requests, allowing the execution of critical functionalities via spoofed requests. This behavior could be abused by a remote unauthenticated attacker to trick Sitemagic users into performing unwarranted actions.

CVE-2019-18219 sitemagic vulnerability CVSS: 4.3 23 Oct 2019, 14:15 UTC

Sitemagic CMS 4.4.1 is affected by a Cross-Site-Scripting (XSS) vulnerability, as it fails to validate user input. The affected components (index.php, upgrade.php) allow for JavaScript injection within both GET or POST requests, via a crafted URL or via the UpgradeMode POST parameter.

CVE-2019-10238 sitemagic vulnerability CVSS: 4.3 27 Mar 2019, 18:29 UTC

Sitemagic CMS v4.4 has XSS in SMFiles/FrmUpload.class.php via the filename parameter.

CVE-2019-9042 sitemagic vulnerability CVSS: 6.5 23 Feb 2019, 18:29 UTC

An issue was discovered in Sitemagic CMS v4.4. In the index.php?SMExt=SMFiles URI, the user can upload a .php file to execute arbitrary code, as demonstrated by 404.php. This can only occur if the administrator neglects to set FileExtensionFilter and there are untrusted user accounts. NOTE: The maintainer states that this is not a vulnerability but a feature used in conjunction with External Modules