N/A Unfixed Closed
2026-03-20≤ 2.288
CMS Commander <= 2.288 - Authenticated (Custom+) SQL Injection via 'or_blogname' Parameter
CMS Commander <= 2.288 - Authenticated (Custom+) SQL Injection via 'or_blogname' Parameter
CVE-2023-3325
CMS Commander – Manage Multiple Sites Plugin <= 2.21 - PHP Object Injection
CMS Commander Client <= 2.21 - Unauthenticated PHP Object Injection