VYPR

Mcms

by Mingsoft

Source repositories

CVEs (52)

  • CVE-2026-4953HigMar 27, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request…

  • CVE-2021-46062HigFeb 18, 2022
    risk 0.46cvss 7.1epss 0.01

    MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.

  • CVE-2025-60838MedOct 10, 2025
    risk 0.42cvss 6.5epss 0.00

    An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2026-4954MedMar 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated…

  • CVE-2022-4375MedDec 9, 2022
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2025-60837MedOct 23, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

  • CVE-2026-19357MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released…

  • CVE-2026-19356MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-2666MedFeb 18, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched…

  • CVE-2023-3990LowJul 28, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate…

  • CVE-2022-4640LowDec 21, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been…

  • CVE-2022-4350LowDec 8, 2022
    risk 0.23cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit…

Page 3 of 3