Critical severity9.8NVD Advisory· Published Oct 17, 2025· Updated Jun 17, 2026
CVE-2025-56316
CVE-2025-56316
Description
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
net.mingsoft:ms-mcmsMaven | >= 5.5.0, < 6.0.2 | 6.0.2 |
Affected products
4- MCMS/MCMSdescription
Patches
Vulnerability mechanics
References
4- gist.github.com/Erosion2020/5892757e0c6eeb647a218d1c3b323cffnvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-54wc-49qj-5ghjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-56316ghsaADVISORY
- github.com/ming-soft/MCMS/commit/35ccbf1e3d38ab6aa178524a47c38dff6b448b59ghsaWEB
News mentions
0No linked articles in our index yet.