Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CMSmap — CMSmap 是一个 Python 开源 CMS 扫描器,可自动检测最流行 CMS 的安全漏洞。 | Kitploit
工具/GitHubGitHub/dionach/cmsmap
漏洞扫描器信息收集Web安全
GitHubdionach/cmsmap

CMSmap

CMSmap 是一个 Python 开源 CMS 扫描器,可自动检测最流行 CMS 的安全漏洞。

查看仓库
1.2k26897年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

CMSmap

CMSmap 是一个 Python 开源 CMS 扫描器,能够自动化检测主流内容管理系统(CMS)的安全漏洞。其核心目标是将不同 CMS 类型的常见漏洞整合到单一工具中。

目前,CMSmap 支持的 CMS 包括 WordPress、Joomla、Drupal 和 Moodle。

请注意,该项目尚处于早期阶段。因此,您可能会遇到错误、缺陷或功能异常。 请自行承担使用风险!

预览

  • https://asciinema.org/a/MELa2nUcrtATqnDLnc0ig8rcT

安装

您可以通过克隆 GitHub 仓库来下载最新版本的 CMSmap:

 git clone https://github.com/Dionach/CMSmap

然后需要在 cmsmap.conf 中配置 edbtype 和 edbpath 设置。如果您有 Exploit-db 的本地 Git 仓库,请使用 GIT:

[exploitdb]
edbtype = GIT
edbpath = /opt/exploitdb/

或者,如果您已安装 debian 的 exploitdb 软件包,请使用 APT。对于 Kali 系统,请使用以下设置:

[exploitdb]
edbtype = APT
edbpath = /usr/share/exploitdb/

如果您希望从系统的任何位置运行 cmsmap,可以使用 pip3 进行安装:

cd CMSmap
pip3 install .

要卸载它:

pip3 uninstall cmsmap -y

用法

usage: cmsmap [-f W/J/D] [-F] [-t] [-a] [-H] [-i] [-o] [-E] [-d] [-u] [-p]
              [-x] [-k] [-w] [-v] [-h] [-D] [-U W/J/D]
              [target]

CMSmap tool v1.0 - Simple CMS Scanner
Author: Mike Manzotti

Scan:
  target                target URL (e.g. 'https://example.com:8080/')
  -f W/J/D, --force W/J/D
                        force scan (W)ordpress, (J)oomla or (D)rupal
  -F, --fullscan        full scan using large plugin lists. False positives and slow!
  -t , --threads        number of threads (Default 5)
  -a , --agent          set custom user-agent
  -H , --header         add custom header (e.g. 'Authorization: Basic ABCD...')
  -i , --input          scan multiple targets listed in a given file
  -o , --output         save output in a file
  -E, --noedb           enumerate plugins without searching exploits
  -c, --nocleanurls     disable clean urls for Drupal only
  -s, --nosslcheck      don't validate the server's certificate
  -d, --dictattack      run low intense dictionary attack during scanning (5 attempts per user)

Brute-Force:
  -u , --usr            username or username file
  -p , --psw            password or password file
  -x, --noxmlrpc        brute forcing WordPress without XML-RPC

Post Exploitation:
  -k , --crack          password hashes file (Require hashcat installed. For WordPress and Joomla only)
  -w , --wordlist       wordlist file

Others:
  -v, --verbose         verbose mode (Default false)
  -h, --help            show this help message and exit
  -D, --default         rum CMSmap with default options
  -U, --update          use (C)MSmap, (P)lugins or (PC) for both

Examples:
  cmsmap.py https://example.com
  cmsmap.py https://example.com -f W -F --noedb -d
  cmsmap.py https://example.com -i targets.txt -o output.txt
  cmsmap.py https://example.com -u admin -p passwords.txt
  cmsmap.py -k hashes.txt -w passwords.txt

贡献指南

如果您想为 CMSmap 做出贡献,请务必查看贡献指南。

免责声明

在未获得双方事先同意的情况下使用 CMSmap 攻击目标是非法的。最终用户有责任遵守所有适用的地方、州和联邦法律。开发者不承担任何责任,也不对因使用本程序而导致的任何滥用或损害负责。

下载工具