Product
murasoftware mura cms
13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-67830
CVE-2025-67829
CVE-2025-55046
CVE-2025-55045
CVE-2025-55044
CVE-2025-55043
CVE-2025-55041
CVE-2025-55040
CVE-2022-47003
CVE-2018-7486
CVE-2017-15639
CVE-2017-8302
CVE-2010-3468
< 10.1.4
Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
< 10.1.4
Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
all versions
MuraCMS through 10.1.10 contains a CSRF vulnerability that allows attackers to permanently destroy all deleted content stored in t
all versions
The update address CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to manipulate user address information through C
all versions
The Trash Restore CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to restore deleted content from the trash to unau
all versions
MuraCMS through 10.1.10 contains a CSRF vulnerability in the bundle creation functionality (csettings.cfc createBundle method) tha
all versions
MuraCMS through 10.1.10 contains a CSRF vulnerability in the Add To Group functionality for user management (cUsers.cfc addToGroup
all versions
The import form CSRF vulnerability in MuraCMS through 10.1.10 allows attackers to upload and install malicious form definitions th
< 10.0.580
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted w
< 7.0.7029
Blue River Mura CMS before v7.0.7029 supports inline function calls with an [m] tag and [/m] end tag, without proper restrictions
<= 6.1
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable
all versions
Mura CMS 7.0.6967 allows admin/?muraAction= XSS attacks, related to admin/core/views/carch/list.cfm, admin/core/views/carch/loadsi
all versions
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 throug