CVE-2023-29963: S-CMS

High severity, CVSS 7.2. EPSS: 1.6% chance of exploitation in the next 30 days.

S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.

Affected products

  • S-CMS S-CMS: version 5.0 only

Published 2023-05-05. Last modified 2026-06-17.