Mcms

Mingsoft · 47 CVEs

CVE-2026-19357
MEDIUM

MingSoft MCMS ms-mdiy get information disclosure

Aug 9, 2026

CVE-2026-19356
MEDIUM

MingSoft MCMS ms-mdiy list information disclosure

Aug 9, 2026

CVE-2026-19355
MEDIUM

MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection

Aug 9, 2026

CVE-2026-4954
MEDIUM

mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection

Mar 27, 2026

CVE-2026-4953
MEDIUM

mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery

Mar 27, 2026

CVE-2026-2666
MEDIUM

mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload

Feb 18, 2026

CVE-2025-60837
MEDIUM

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in…

Oct 23, 2025

CVE-2025-56316
CRITICAL

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows rem…

Oct 17, 2025

CVE-2025-60838
MEDIUM

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafte…

Oct 10, 2025

CVE-2025-29287
CRITICAL

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary co…

Apr 21, 2025

CVE-2024-42991
HIGH

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Sep 3, 2024

CVE-2024-22567
HIGH

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file…

Feb 5, 2024

CVE-2023-51282
HIGH

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to th…

Jan 16, 2024

CVE-2023-50578
CRITICAL

Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content…

Dec 30, 2023

CVE-2023-3990
MEDIUM

Mingsoft MCMS HTTP POST Request search.do cross site scripting

Jul 28, 2023

CVE-2020-22755
HIGH

File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different v…

May 8, 2023

CVE-2020-20913
CRITICAL

SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basi…

Apr 4, 2023

CVE-2022-47042
HIGH

MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/wr…

Jan 24, 2023

CVE-2022-4640
MEDIUM

Mingsoft MCMS Article save cross site scripting

Dec 21, 2022

CVE-2022-4375
CRITICAL

Mingsoft MCMS list sql injection

Dec 9, 2022

CVE-2022-4350
MEDIUM

Mingsoft MCMS search.do cross site scripting

Dec 8, 2022

CVE-2022-36599
CRITICAL

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

Aug 16, 2022

CVE-2022-36272
CRITICAL

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName para…

Aug 16, 2022

CVE-2022-31943
CRITICAL

MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

Jul 1, 2022

CVE-2022-29647
HIGH

An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic…

May 31, 2022

Showing 1 to 25 of 47 CVEs