Mcms
Mingsoft · 47 CVEs
MingSoft MCMS ms-mdiy get information disclosure
Aug 9, 2026
MingSoft MCMS ms-mdiy list information disclosure
Aug 9, 2026
MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection
Aug 9, 2026
mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection
Mar 27, 2026
mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery
Mar 27, 2026
mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload
Feb 18, 2026
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in…
Oct 23, 2025
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows rem…
Oct 17, 2025
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafte…
Oct 10, 2025
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary co…
Apr 21, 2025
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
Sep 3, 2024
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file…
Feb 5, 2024
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to th…
Jan 16, 2024
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content…
Dec 30, 2023
Mingsoft MCMS HTTP POST Request search.do cross site scripting
Jul 28, 2023
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different v…
May 8, 2023
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basi…
Apr 4, 2023
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/wr…
Jan 24, 2023
Mingsoft MCMS Article save cross site scripting
Dec 21, 2022
Mingsoft MCMS list sql injection
Dec 9, 2022
Mingsoft MCMS search.do cross site scripting
Dec 8, 2022
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
Aug 16, 2022
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName para…
Aug 16, 2022
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
Jul 1, 2022
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic…
May 31, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-19357 | MingSoft MCMS ms-mdiy get information disclosure | MEDIUM | 0.48% | Aug 9, 2026 |
| CVE-2026-19356 | MingSoft MCMS ms-mdiy list information disclosure | MEDIUM | 0.48% | Aug 9, 2026 |
| CVE-2026-19355 | MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection | MEDIUM | 0.41% | Aug 9, 2026 |
| CVE-2026-4954 | mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection | MEDIUM | 0.32% | Mar 27, 2026 |
| CVE-2026-4953 | mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery | MEDIUM | 0.47% | Mar 27, 2026 |
| CVE-2026-2666 | mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload | MEDIUM | 0.55% | Feb 18, 2026 |
| CVE-2025-60837 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a c… | MEDIUM | 0.20% | Oct 23, 2025 |
| CVE-2025-56316 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL q… | CRITICAL | 0.64% | Oct 17, 2025 |
| CVE-2025-60838 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | MEDIUM | 0.26% | Oct 10, 2025 |
| CVE-2025-29287 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | CRITICAL | 0.78% | Apr 21, 2025 |
| CVE-2024-42991 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. | HIGH | 0.81% | Sep 3, 2024 |
| CVE-2024-22567 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. | HIGH | 17.79% | Feb 5, 2024 |
| CVE-2023-51282 | An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. | HIGH | 1.12% | Jan 16, 2024 |
| CVE-2023-50578 | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. | CRITICAL | 2.24% | Dec 30, 2023 |
| CVE-2023-3990 | Mingsoft MCMS HTTP POST Request search.do cross site scripting | MEDIUM | 1.43% | Jul 28, 2023 |
| CVE-2020-22755 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. | HIGH | 0.92% | May 8, 2023 |
| CVE-2020-20913 | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter. | CRITICAL | 1.42% | Apr 4, 2023 |
| CVE-2022-47042 | MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do. | HIGH | 1.03% | Jan 24, 2023 |
| CVE-2022-4640 | Mingsoft MCMS Article save cross site scripting | MEDIUM | 0.42% | Dec 21, 2022 |
| CVE-2022-4375 | Mingsoft MCMS list sql injection | CRITICAL | 2.97% | Dec 9, 2022 |
| CVE-2022-4350 | Mingsoft MCMS search.do cross site scripting | MEDIUM | 0.41% | Dec 8, 2022 |
| CVE-2022-36599 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | CRITICAL | 1.09% | Aug 16, 2022 |
| CVE-2022-36272 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter. | CRITICAL | 1.09% | Aug 16, 2022 |
| CVE-2022-31943 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. | CRITICAL | 1.52% | Jul 1, 2022 |
| CVE-2022-29647 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | HIGH | 0.65% | May 31, 2022 |
Showing 1 to 25 of 47 CVEs