CVE-2026-4954
- EPSS 0.03%
- Veröffentlicht 27.03.2026 14:13:38
- Zuletzt bearbeitet 30.03.2026 13:26:29
A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The...
CVE-2026-4953
- EPSS 0.05%
- Veröffentlicht 27.03.2026 14:13:36
- Zuletzt bearbeitet 30.03.2026 13:26:29
A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead...
CVE-2026-2666
- EPSS 0.02%
- Veröffentlicht 18.02.2026 20:18:37
- Zuletzt bearbeitet 19.02.2026 18:36:04
A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload....
CVE-2025-60837
- EPSS 0.02%
- Veröffentlicht 23.10.2025 00:00:00
- Zuletzt bearbeitet 27.10.2025 20:13:17
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.
CVE-2025-56316
- EPSS 0.15%
- Veröffentlicht 17.10.2025 00:00:00
- Zuletzt bearbeitet 28.10.2025 16:44:48
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
CVE-2025-60838
- EPSS 0.04%
- Veröffentlicht 10.10.2025 00:00:00
- Zuletzt bearbeitet 28.10.2025 15:32:01
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2025-29287
- EPSS 1.65%
- Veröffentlicht 21.04.2025 00:00:00
- Zuletzt bearbeitet 24.04.2025 16:37:54
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-42991
- EPSS 2.15%
- Veröffentlicht 03.09.2024 16:15:06
- Zuletzt bearbeitet 30.04.2025 16:42:01
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
CVE-2024-22567
- EPSS 1.5%
- Veröffentlicht 05.02.2024 20:15:55
- Zuletzt bearbeitet 17.06.2025 15:15:39
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
CVE-2023-51282
- EPSS 0.21%
- Veröffentlicht 16.01.2024 02:15:28
- Zuletzt bearbeitet 17.06.2025 15:15:36
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.