melisplatform/melis-cms
MelisCms provides a full CMS for Melis Platform, including templating system, drag'n'drop of plugins, SEO and many administration tools.
Activity
- Latest release
- 3w ago
- Total releases
- 103
- Cadence
- ~21 days
- Last 12 months
- 21
Reach
- Stars
- 10
Details
- License
- unknown
- First release
- May 16, 2017
| Version | Released | |
|---|---|---|
v6.0.3
patch
| ||
v6.0.2
patch
| ||
v6.0.1
patch
| ||
v6.0.0
major
| ||
v5.3.29
patch
| ||
v5.3.28
patch
| ||
v5.3.27
patch
| ||
v5.3.26
patch
| ||
v5.3.25
patch
| ||
v5.3.24
patch
| ||
v5.3.23
patch
| ||
v5.3.22
patch
| ||
v5.3.21
patch
| ||
v5.3.20
patch
| ||
v5.3.19
patch
| ||
v5.3.18
patch
| ||
v5.3.17
patch
| ||
v5.3.16
patch
| ||
v5.3.15
patch
| ||
v5.3.14
patch
| ||
v5.3.13
patch
| ||
v5.3.12
patch
| ||
v5.3.11
patch
| ||
v5.3.10
patch
| ||
v5.3.9
patch
| ||
v5.3.8
patch
| ||
v5.3.7
patch
| ||
v5.3.6
patch
| ||
v5.3.5
patch
| ||
v5.3.4
patch
| ||
v5.3.3
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.3.2
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.3.1
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.3.0
minor
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.2.2
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.2.1
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.2.0
minor
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.1.1
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.1.0
minor
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.0.1
patch
1 CVE
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev | ||
v5.0.0
major
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.1.2
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.1.1
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.1.0
minor
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.0.11
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.0.10
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.0.9
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.0.8
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.0.7
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v4.0.6
patch
2 CVEs
CVE-2025-10351
GHSA-mrmx-jfw8-qhgv
Oct 08, 2025
Melis Platform CMS SQL Injection
Critical
Network
Low
None
None
SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'idPage' parameter in the '/melis/MelisCms/PageEdition/getTinyTemplates' endpoint. Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 62 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
v5.0.1
v5.1.0
v5.1.1
v5.2.0
v5.2.1
v5.2.2
v5.3.0
v5.3.1
v5.3.2
v5.3.3
Fixed in
5.3.4
References
Updated Oct 09, 2025 · Source: OSV.dev
CVE-2022-39297
GHSA-m3m3-6gww-7gj9
Oct 11, 2022
melisplatform/melis-cms vulnerable to deserialization of untrusted data
7.7
/ 10
High
Network
High
None
None
Unchanged
High
High
Low
ImpactAttackers can deserialize arbitrary data on affected versions of Users should immediately upgrade to PatchesThis issue was addressed by restricting allowed classes when deserializing user-controlled data. References
For more informationIf you have any questions or comments about this advisory, you can contact:
Affected versions
v2.1
v2.1.1
v2.2.0
v2.2.1
v2.3.0
v2.3.1
v2.4.0
v2.5.0
v3.0.0
v3.0.1
v3.0.10
v3.0.2
+ 52 more Show less
v3.0.3
v3.0.4
v3.0.5
v3.0.6
v3.0.7
v3.0.8
v3.0.9
v3.1.0
v3.1.1
v3.1.10
v3.1.11
v3.1.12
v3.1.13
v3.1.2
v3.1.3
v3.1.4
v3.1.5
v3.1.6
v3.1.7
v3.1.8
v3.1.9
v3.2.0
v3.2.1
v3.2.10
v3.2.11
v3.2.12
v3.2.13
v3.2.14
v3.2.2
v3.2.3
v3.2.4
v3.2.5
v3.2.6
v3.2.7
v3.2.8
v3.2.9
v4.0.0
v4.0.1
v4.0.10
v4.0.11
v4.0.2
v4.0.3
v4.0.4
v4.0.5
v4.0.6
v4.0.7
v4.0.8
v4.0.9
v4.1.0
v4.1.1
v4.1.2
v5.0.0
Fixed in
5.0.1
References Updated Nov 08, 2023 · Source: OSV.dev |