CVE-2022-47003
Critical · CVSS 9.8Mura CMS — Authentication Bypass via Remember Me function
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- NVD-CWE-Other, CWE-287
Description
A vulnerability in the Remember Me function of Mura CMS before v10.0.580 allows attackers to bypass authentication via a crafted web request.
Search profile — drives PoC discovery
Symbols Remember MerememberMeauthenticationcrafted web requestcookiebypass
Keywords CVE-2022-47003Mura CMSauthentication bypassRemember MeMuraCMSMasaCMSv10.0.580CWE-287
Versions: before v10.0.580
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0IIDavi/WordPress-Mura-CMS-Checker needs reviewtrickest
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html
- https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html
- https://www.masacms.com/
- https://www.murasoftware.com/mura-cms/
- http://mura.com
- https://hoyahaxa.blogspot.com/2023/01/preliminary-security-advisory.html
- https://hoyahaxa.blogspot.com/2023/03/authentication-bypass-mura-masa.html
- https://www.masacms.com/
- https://www.murasoftware.com/mura-cms/
Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T12:30:39.000Z