Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2021-45787 1 Maccms 1 Maccms 2024-11-21 5.4 Medium
There is a stored Cross Site Scripting (XSS) vulnerability in maccms v10 through adding videos. XSS code can be inserted at parameter positions including name and remarks.
CVE-2021-45786 1 Maccms 1 Maccms 2024-11-21 9.8 Critical
In maccms v10, an attacker can log in through /index.php/user/login in the "col" and "openid" parameters to gain privileges.