Mingsoft / Mcms
47 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-19357 | MingSoft MCMS ms-mdiy get information disclosure | MEDIUM | 6.9 | Aug 9, 2026 |
| CVE-2026-19356 | MingSoft MCMS ms-mdiy list information disclosure | MEDIUM | 6.9 | Aug 9, 2026 |
| CVE-2026-19355 | MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection | MEDIUM | 6.9 | Aug 9, 2026 |
| CVE-2026-4954 | mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection | MEDIUM | 5.3 | Mar 27, 2026 |
| CVE-2026-4953 | mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery | MEDIUM | 6.9 | Mar 27, 2026 |
| CVE-2026-2666 | mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload | MEDIUM | 5.1 | Feb 18, 2026 |
| CVE-2025-60837 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a c… | MEDIUM | 6.1 | Oct 23, 2025 |
| CVE-2025-56316 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL q… | CRITICAL | 9.8 | Oct 17, 2025 |
| CVE-2025-60838 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | MEDIUM | 6.5 | Oct 10, 2025 |
| CVE-2025-29287 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. | CRITICAL | 9.8 | Apr 21, 2025 |
| CVE-2024-42991 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. | HIGH | 8.1 | Sep 3, 2024 |
| CVE-2024-22567 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. | HIGH | 8.8 | Feb 5, 2024 |
| CVE-2023-51282 | An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. | HIGH | 7.5 | Jan 16, 2024 |
| CVE-2023-50578 | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. | CRITICAL | 9.8 | Dec 30, 2023 |
| CVE-2023-3990 | Mingsoft MCMS HTTP POST Request search.do cross site scripting | MEDIUM | 6.1 | Jul 28, 2023 |
| CVE-2020-22755 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. | HIGH | 8.8 | May 8, 2023 |
| CVE-2020-20913 | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter. | CRITICAL | 9.8 | Apr 4, 2023 |
| CVE-2022-47042 | MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do. | HIGH | 8.8 | Jan 24, 2023 |
| CVE-2022-4640 | Mingsoft MCMS Article save cross site scripting | MEDIUM | 5.4 | Dec 21, 2022 |
| CVE-2022-4375 | Mingsoft MCMS list sql injection | CRITICAL | 9.8 | Dec 9, 2022 |
| CVE-2022-4350 | Mingsoft MCMS search.do cross site scripting | MEDIUM | 6.1 | Dec 8, 2022 |
| CVE-2022-36599 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | CRITICAL | 9.8 | Aug 16, 2022 |
| CVE-2022-36272 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter. | CRITICAL | 9.8 | Aug 16, 2022 |
| CVE-2022-31943 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. | CRITICAL | 9.8 | Jul 1, 2022 |
| CVE-2022-29647 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. | HIGH | 8.8 | May 31, 2022 |
Showing 1 to 25 of 47 CVEs