Home/Product/mingsoft mcms
Product

mingsoft mcms

48 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-2666
all versions
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do o
4.7MEDIUM
CVE-2025-60837
<= 6.0.1
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the contex
6.1MEDIUM
CVE-2025-56316
all versions
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attacke
9.8CRITICAL
CVE-2025-60838
<= 6.0.1
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.
6.5MEDIUM
CVE-2025-29287
all versions
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uplo
9.8CRITICAL
CVE-2024-42991
all versions
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
8.1HIGH
CVE-2024-22567
all versions
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
8.8HIGH
CVE-2023-51282
all versions
An issue in mingSoft MCMS v.5.2.4 allows a remote attacker to obtain sensitive information via a crafted script to the password
7.5HIGH
CVE-2023-50578
all versions
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
9.8CRITICAL
CVE-2023-3990
<= 5.3.1
A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file se
3.5LOW
CVE-2020-22755
all versions
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerabilit
8.8HIGH
CVE-2020-20913
all versions
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title par
9.8CRITICAL
CVE-2022-47042
all versions
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileCont
8.8HIGH
CVE-2022-4640
all versions
A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the functio
3.5LOW
CVE-2022-4375
< 5.2.10
A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the
6.3MEDIUM
CVE-2022-4350
all versions
A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the fil
3.5LOW
CVE-2022-36599
all versions
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
9.8CRITICAL
CVE-2022-36272
all versions
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
9.8CRITICAL
CVE-2022-31943
all versions
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
9.8CRITICAL
CVE-2022-30506
all versions
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a craf
9.8CRITICAL
CVE-2022-29647
all versions
An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/sa
8.8HIGH
CVE-2022-30048
all versions
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
9.8CRITICAL
CVE-2022-30047
all versions
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy paramete
9.8CRITICAL
CVE-2022-27466
all versions
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
9.8CRITICAL
CVE-2022-27340
all versions
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to esc
8.8HIGH
CVE-2022-26585
all versions
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
9.8CRITICAL
CVE-2021-46384
<= 5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vecto
9.8CRITICAL
CVE-2022-25125
all versions
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
9.8CRITICAL
CVE-2022-23899
all versions
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
9.8CRITICAL
CVE-2022-23898
all versions
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
9.8CRITICAL
CVE-2021-46063
all versions
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
9.1CRITICAL
CVE-2021-46062
all versions
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
7.1HIGH
CVE-2021-46037
all versions
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
8.1HIGH
CVE-2021-46036
all versions
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbi
9.8CRITICAL
CVE-2021-44868
all versions
A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do
9.8CRITICAL
CVE-2021-46385
<= 5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).
7.5HIGH
CVE-2021-46386
<= 5.2.5
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx web
9.8CRITICAL
CVE-2021-46383
<= 5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote).
7.5HIGH
CVE-2022-23315
all versions
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
9.8CRITICAL
CVE-2022-23314
all versions
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
9.8CRITICAL
CVE-2022-22930
all versions
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitra
9.8CRITICAL
CVE-2022-22929
all versions
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to ex
9.8CRITICAL
CVE-2022-22928
all versions
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
9.8CRITICAL
CVE-2020-23262
all versions
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/
9.8CRITICAL
CVE-2018-18831
all versions
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the p
7.5HIGH
CVE-2018-18830
all versions
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify
9.8CRITICAL
CVE-2018-17366
all versions
An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/sa
8.8HIGH
CVE-2007-6344
all versions
Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include and execu
threatengine.sh