Mingsoft

Mcms

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 18.02.2026 20:18:37
  • Zuletzt bearbeitet 19.02.2026 18:36:04

A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload....

  • EPSS 0.05%
  • Veröffentlicht 23.10.2025 00:00:00
  • Zuletzt bearbeitet 27.10.2025 20:13:17

A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 17.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 16:44:48

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

  • EPSS 0.08%
  • Veröffentlicht 10.10.2025 00:00:00
  • Zuletzt bearbeitet 28.10.2025 15:32:01

An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 1.65%
  • Veröffentlicht 21.04.2025 00:00:00
  • Zuletzt bearbeitet 24.04.2025 16:37:54

An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

Exploit
  • EPSS 2.15%
  • Veröffentlicht 03.09.2024 16:15:06
  • Zuletzt bearbeitet 30.04.2025 16:42:01

MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

Exploit
  • EPSS 1.5%
  • Veröffentlicht 05.02.2024 20:15:55
  • Zuletzt bearbeitet 17.06.2025 15:15:39

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 16.01.2024 02:15:28
  • Zuletzt bearbeitet 17.06.2025 15:15:36

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

Exploit
  • EPSS 31.69%
  • Veröffentlicht 30.12.2023 16:15:44
  • Zuletzt bearbeitet 21.11.2024 08:37:05

Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.

Exploit
  • EPSS 10.29%
  • Veröffentlicht 28.07.2023 07:15:09
  • Zuletzt bearbeitet 21.11.2024 08:18:29

A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting...