MCMS
by Mcms
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-27340 | Hig | 0.57 | 8.8 | 0.01 | Apr 22, 2022 | MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data. | ||
| CVE-2024-42991 | Hig | 0.53 | 8.1 | 0.01 | Sep 3, 2024 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. | ||
| CVE-2021-46037 | Hig | 0.53 | 8.1 | 0.01 | Feb 18, 2022 | MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do. | ||
| CVE-2021-46062 | Hig | 0.46 | 7.1 | 0.01 | Feb 18, 2022 | MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName. | ||
| CVE-2025-60838 | Med | 0.42 | 6.5 | 0.00 | Oct 10, 2025 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2025-60837 | Med | 0.40 | 6.1 | 0.00 | Oct 23, 2025 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. | ||
| CVE-2026-52203 | Hig | 0.00 | 7.5 | 0.01 | Jul 17, 2026 | An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. |
- risk 0.57cvss 8.8epss 0.01
MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.
- risk 0.53cvss 8.1epss 0.01
MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.
- risk 0.53cvss 8.1epss 0.01
MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.
- risk 0.46cvss 7.1epss 0.01
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
- risk 0.42cvss 6.5epss 0.00
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.40cvss 6.1epss 0.00
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.
- risk 0.00cvss 7.5epss 0.01
An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.
Page 2 of 2