CVE-2024-32640: Masacms
Critical severity, CVSS 9.8. EPSS: 76.6% chance of exploitation in the next 30 days.
MASA CMS is an Enterprise Content Management platform based on open source technology. Versions prior to 7.4.5, 7.3.12, and 7.2.7 contain a SQL injection vulnerability in the `processAsyncObject` method that can result in remote code execution. Versions 7.4.5, 7.3.12, and 7.2.7 contain a fix for the issue.
Affected products
- Masacms Masacms: from 7.4.0, before 7.4.5 (fixed in 7.4.5); from 7.3.0, before 7.3.12 (fixed in 7.3.12); before 7.2.7 (fixed in 7.2.7)
Published 2025-08-11. Last modified 2026-06-17.