Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
We have discovered 984 live websites that are affected by CVE-2025-67830.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 984 live websites (100% of Mura CMS install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 66 versions ( 97% of all versions) |
| 569 websites | |
| 94 websites | |
| 61 websites | |
| 60 websites | |
| 43 websites | |
| 37 websites | |
| 34 websites | |
| 26 websites | |
| 20 websites | |
| 9 websites |
| .com | 373 websites |
| .org | 162 websites |
| .ch | 60 websites |
| .co.uk | 47 websites |
| .it | 37 websites |
| .edu | 26 websites |
| .net | 25 websites |
| .nl | 23 websites |
| .ca | 20 websites |
| .com.au | 20 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****.com | *,*** | ||
| ***********.info | **,*** | ||
| ***.gov | **,*** | ||
| *******.org | **,*** | ||
| ***.***.wales | **,*** | ||
| ***.***.uk | **,*** | ||
| **********.com | **,*** | ||
| ****.org | **,*** | ||
| **.**.gov | **,*** | ||
| *****.org | **,*** |