VYPR

MCMS

by Mcms

CVEs (27)

  • CVE-2022-22930CriJan 21, 2022
    risk 0.66cvss 9.8epss 0.24

    A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2026-68000CriAug 26, 2026
    risk 0.64cvss 9.8epss 0.00

    The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directly concatenated into the LIMIT clause of SQL through FreeMarker ${size} without being parameterized and bound. The built-in SqlInjectionUtil employs regular…

  • CVE-2025-29287CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2022-31943CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2022-30506CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

  • CVE-2022-27466CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

  • CVE-2021-46384CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated…

  • CVE-2022-25125CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.07

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.

  • CVE-2022-23899CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.

  • CVE-2022-23898CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.08

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.

  • CVE-2021-46036CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.

  • CVE-2022-23315CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

  • CVE-2022-23314CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

  • CVE-2022-22929CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2022-22928CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

  • CVE-2021-46063CriFeb 18, 2022
    risk 0.59cvss 9.1epss 0.03

    MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

  • CVE-2025-56316CriOct 17, 2025
    risk 0.57cvss 9.8epss 0.01

    A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

  • CVE-2020-22755HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.

  • CVE-2022-47042HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.

  • CVE-2022-29647HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

Page 1 of 2