VYPR

Vendor CVEs

Mingsoft

All CVEs

52 total · sorted by risk
  • CVE-2022-22930CriJan 21, 2022
    risk 0.66cvss 9.8epss 0.24

    A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

  • CVE-2025-29287CriApr 21, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-50578CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.

  • CVE-2020-20913CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.

  • CVE-2022-36599CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

  • CVE-2022-36272CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

  • CVE-2022-31943CriJul 1, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

  • CVE-2022-30506CriJun 2, 2022
    risk 0.64cvss 9.8epss 0.03

    An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

  • CVE-2022-30048CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.

  • CVE-2022-30047CriMay 11, 2022
    risk 0.64cvss 9.8epss 0.01

    Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.

  • CVE-2022-27466CriMay 2, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

  • CVE-2022-26585CriApr 5, 2022
    risk 0.64cvss 9.8epss 0.06

    Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

  • CVE-2021-46384CriMar 4, 2022
    risk 0.64cvss 9.8epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated…

  • CVE-2022-25125CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.07

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.

  • CVE-2022-23899CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.01

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.

  • CVE-2022-23898CriMar 3, 2022
    risk 0.64cvss 9.8epss 0.08

    MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.

  • CVE-2021-46036CriFeb 18, 2022
    risk 0.64cvss 9.8epss 0.04

    An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.

  • CVE-2021-44868CriFeb 17, 2022
    risk 0.64cvss 9.8epss 0.01

    A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do

  • CVE-2021-46386CriJan 26, 2022
    risk 0.64cvss 9.8epss 0.03

    File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

  • CVE-2022-23315CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

  • CVE-2022-23314CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.02

    MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

  • CVE-2022-22929CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

  • CVE-2022-22928CriJan 21, 2022
    risk 0.64cvss 9.8epss 0.03

    MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

  • CVE-2020-23262CriJan 26, 2021
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

  • CVE-2018-18830CriOct 30, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename,…

  • CVE-2024-22567HigFeb 5, 2024
    risk 0.59cvss 8.8epss 0.18

    File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

  • CVE-2021-46063CriFeb 18, 2022
    risk 0.59cvss 9.1epss 0.03

    MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

  • CVE-2025-56316CriOct 17, 2025
    risk 0.57cvss 9.8epss 0.01

    A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

  • CVE-2020-22755HigMay 8, 2023
    risk 0.57cvss 8.8epss 0.01

    File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.

  • CVE-2022-47042HigJan 26, 2023
    risk 0.57cvss 8.8epss 0.01

    MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.

  • CVE-2022-29647HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

  • CVE-2022-27340HigApr 22, 2022
    risk 0.57cvss 8.8epss 0.01

    MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.

  • CVE-2018-17366HigSep 23, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in MCMS 4.6.5. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

  • CVE-2024-42991HigSep 3, 2024
    risk 0.53cvss 8.1epss 0.01

    MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution.

  • CVE-2021-46037HigFeb 18, 2022
    risk 0.53cvss 8.1epss 0.01

    MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.

  • CVE-2023-51282HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

  • CVE-2021-46385HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2021-46383HigJan 26, 2022
    risk 0.49cvss 7.5epss 0.02

    https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability…

  • CVE-2018-18831HigOct 30, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.

  • CVE-2026-19355HigAug 9, 2026
    risk 0.47cvss 7.3epss 0.00

    A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be…

  • CVE-2026-4953HigMar 27, 2026
    risk 0.47cvss 7.3epss 0.00

    A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request…

  • CVE-2021-46062HigFeb 18, 2022
    risk 0.46cvss 7.1epss 0.01

    MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.

  • CVE-2025-60838MedOct 10, 2025
    risk 0.42cvss 6.5epss 0.00

    An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2026-4954MedMar 27, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated…

  • CVE-2022-4375MedDec 9, 2022
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2025-60837MedOct 23, 2025
    risk 0.40cvss 6.1epss 0.00

    A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.

  • CVE-2026-19357MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible to launch the attack remotely. The exploit has been released…

  • CVE-2026-19356MedAug 9, 2026
    risk 0.34cvss 5.3epss 0.00

    A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible to initiate the attack remotely. The exploit is publicly…

  • CVE-2026-2666MedFeb 18, 2026
    risk 0.31cvss 4.7epss 0.00

    A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File can lead to unrestricted upload. The attack can be launched…

  • CVE-2023-3990LowJul 28, 2023
    risk 0.23cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate…

Page 1 of 2