Mingsoft

Mcms

52 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 09.08.2026 14:45:07
  • Zuletzt bearbeitet 12.08.2026 20:59:21

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. T...

  • EPSS 0.29%
  • Veröffentlicht 09.08.2026 13:45:07
  • Zuletzt bearbeitet 13.08.2026 20:17:20

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely....

  • EPSS 0.25%
  • Veröffentlicht 09.08.2026 13:30:09
  • Zuletzt bearbeitet 12.08.2026 20:59:21

A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql in...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 27.03.2026 14:13:38
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 27.03.2026 14:13:36
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 18.02.2026 20:18:37
  • Zuletzt bearbeitet 29.04.2026 01:00:01

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload....

  • EPSS 0.19%
  • Veröffentlicht 23.10.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 02:17:15

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

Exploit
  • EPSS 0.59%
  • Veröffentlicht 17.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 16:44:48

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

  • EPSS 0.25%
  • Veröffentlicht 10.10.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 02:17:15

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 0.73%
  • Veröffentlicht 21.04.2025 00:00:00
  • Zuletzt bearbeitet 05.07.2026 01:21:39

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.