VYPR

Mcms

by Mingsoft

Source repositories

CVEs (52)

  • CVE-2022-23314CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

  • CVE-2022-22929CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2022-22928CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

  • CVE-2020-23262CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

  • CVE-2018-18830CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename,…

  • CVE-2024-22567HigFeb 5, 2024
    risk 0.59cvss 8.8epss 0.18

    File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

  • CVE-2021-46063CriFeb 18, 2022
    risk 0.59cvss 9.1epss 0.03

    MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

  • CVE-2025-56316CriOct 17, 2025
    risk 0.57cvss 9.8epss 0.01

    A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

  • CVE-2020-22755HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.

  • CVE-2022-47042HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.

  • CVE-2022-29647HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

  • CVE-2022-27340HigApr 22, 2022
    risk 0.57cvss 8.8epss 0.01

    MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.

  • CVE-2018-17366HigSep 23, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

  • CVE-2024-42991HigSep 3, 2024
    risk 0.53cvss 8.1epss 0.01

    MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

  • CVE-2021-46037HigFeb 18, 2022
    risk 0.53cvss 8.1epss 0.01

    MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.

  • CVE-2023-51282HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

  • CVE-2021-46385HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2021-46383HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2018-18831HigOct 30, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.

  • CVE-2026-19355HigAug 9, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be…