CVE-2022-47002: Masacms

Critical severity, CVSS 9.8. EPSS: 6.3% chance of exploitation in the next 30 days.

A vulnerability in the Remember Me function of Masa CMS v7.2, 7.3, and 7.4-beta allows attackers to bypass authentication via a crafted web request.

Affected products

  • Masacms Masacms: before 7.2.5 (fixed in 7.2.5); from 7.3, before 7.3.10 (fixed in 7.3.10); version 7.4.0 only

Published 2023-02-01. Last modified 2026-06-17.