LIVE · cybersecurity feed
Live wire
vendor

Murasoftware

8 CVEs published in the last four months. Exploited flaws first.

Critical2
High5
Medium1
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2025-678309.8criticalmura cmsMura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.171d ago
CVE-2025-678299.8criticalmura cmsMura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.171d ago
CVE-2025-550408.8highmura cmsThe import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious for171d ago
CVE-2025-550448.8highmura cmsThe Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from t171d ago
CVE-2025-550468.1highmura cmsMuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted con171d ago
CVE-2025-550418highmura cmsMuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUser171d ago
CVE-2025-550457.1highmura cmsThe update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address infor171d ago
CVE-2025-550436.5mediummura cmsMuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBu171d ago

Filter the full tracker by Murasoftware