Magnussolution Magnusbilling vulnerabilities
4 known vulnerabilities affecting magnussolution/magnusbilling.
Total CVEs
4
CISA KEV
0
Public exploits
3
Exploited in wild
3
Severity breakdown
CRITICAL1HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-30258P1CRITICALCVSS 9.8ExploitedPoC≥ 6.0.0, ≤ 7.3.02023-06-23
CVE-2023-30258 [CRITICAL] CWE-78 CVE-2023-30258: Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
nvd
CVE-2025-2609P2MEDIUMCVSS 6.1ExploitedPoC≤ 7.3.02025-03-21
CVE-2025-2609 [MEDIUM] CWE-79 CVE-2025-2609: Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBi
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.
nvd
CVE-2025-2610P2MEDIUMCVSS 5.4ExploitedPoC≤ 7.3.02025-03-21
CVE-2025-2610 [MEDIUM] CWE-79 CVE-2025-2610: Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBi
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.
This issue affects MagnusBilling: through 7.3.0.
nvd
CVE-2025-52289P3HIGHCVSS 8.0v7.8.5.32025-07-31
CVE-2025-52289 [HIGH] CWE-269 CVE-2025-52289: A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gai
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
nvd