m
masacms
Security Risk Profile
65
/100
highSecurity Risk Score
Comprehensive risk assessment based on 6 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 5, 2022 to present
6
Total CVEs
6
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
8.6
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
65/100
high
Severity Distribution
Critical
2High
4Medium
0Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
XSS
1
2
Code Injection
1
3
Path Traversal
1
Most Affected Products
1. MasaCMS MasaCMS20
2. MASA CMS3
3. Masa CMS Masa CMS1
Recent Vulnerabilities
See more →CVE-2025-66492
CVSS 8.2high
Masa CMS vulnerable to Cross-Site Scripting (XSS) through URL Parameter
Dec 12, 2025
CVE-2024-32643
CVSS 7.5high
Masa CMS vulnerable to authentication bypass with /tag/
Dec 3, 2025
CVE-2024-32642
CVSS 8.8high
Host header poisoning allows account takeover via password reset email
Dec 3, 2025
CVE-2024-32641
CVSS 9.8critical
Masa CMS Vulnerable to Pre-Auth RCE via JSON API
Dec 3, 2025
CVE-2022-47002
CVSS 9.8critical
Feb 1, 2023
CVE-2021-42183
CVSS 7.5high
May 5, 2022🔧 No Patch
Monitor masacms in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.