Mingsoft

Mcms

49 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 27.03.2026 14:13:38
  • Zuletzt bearbeitet 30.03.2026 13:26:29

A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 27.03.2026 14:13:36
  • Zuletzt bearbeitet 30.03.2026 13:26:29

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 18.02.2026 20:18:37
  • Zuletzt bearbeitet 19.02.2026 18:36:04

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload....

  • EPSS 0.02%
  • Veröffentlicht 23.10.2025 00:00:00
  • Zuletzt bearbeitet 27.10.2025 20:13:17

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 17.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 16:44:48

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

  • EPSS 0.04%
  • Veröffentlicht 10.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 15:32:01

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 1.65%
  • Veröffentlicht 21.04.2025 00:00:00
  • Zuletzt bearbeitet 24.04.2025 16:37:54

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 2.15%
  • Veröffentlicht 03.09.2024 16:15:06
  • Zuletzt bearbeitet 30.04.2025 16:42:01

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Exploit
  • EPSS 1.5%
  • Veröffentlicht 05.02.2024 20:15:55
  • Zuletzt bearbeitet 17.06.2025 15:15:39

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 16.01.2024 02:15:28
  • Zuletzt bearbeitet 17.06.2025 15:15:36

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.