Mingsoft
Mingsoft Mcms: vulnerabilidades y CVE
Mingsoft Mcms tiene 52 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 28 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE52
Últimos 12 meses9
Críticas28
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-19357 | Media (5.5) | 0.48% | — | 9 ago 2026 | A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy. The manipulation results in information disclosure. It is possible… |
| CVE-2026-19356 | Media (5.5) | 0.48% | — | 9 ago 2026 | A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-mdiy. The manipulation leads to information disclosure. It is possible… |
| CVE-2026-19355 | Media (5.5) | 0.41% | — | 9 ago 2026 | A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the… |
| CVE-2026-4954 | Baja (2.1) | 0.32% | — | 27 mar 2026 | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The… |
| CVE-2026-4953 | Media (5.5) | 0.47% | — | 27 mar 2026 | A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of… |
| CVE-2026-2666 | Baja (2) | 0.55% | — | 18 feb 2026 | A flaw has been found in mingSoft MCMS 6.1.1. The affected element is an unknown function of the file /ms/file/uploadTemplate.do of the component Template Archive Handler. Executing a manipulation of the argument File… |
| CVE-2025-60837 | Media (6.1) | 0.20% | — | 23 oct 2025 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload. |
| CVE-2025-56316 | Crítica (9.8) | 0.64% | — | 17 oct 2025 | A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template… |
| CVE-2025-60838 | Media (6.5) | 0.26% | — | 10 oct 2025 | An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file. |
| CVE-2025-29287 | Crítica (9.8) | 0.78% | — | 21 abr 2025 | An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file. |
| CVE-2024-42991 | Alta (8.1) | 0.81% | — | 3 sept 2024 | MCMS v5.4.1 has front-end file upload vulnerability which can lead to remote command execution. |
| CVE-2024-22567 | Alta (8.8) | 18% | — | 5 feb 2024 | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. |
| CVE-2023-51282 | Alta (7.5) | 1.1% | — | 16 ene 2024 | An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. |
| CVE-2023-50578 | Crítica (9.8) | 2.2% | — | 30 dic 2023 | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. |
| CVE-2023-3990 | Media (6.1) | 1.4% | — | 28 jul 2023 | A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument… |
| CVE-2020-22755 | Alta (8.8) | 0.92% | — | 8 may 2023 | File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943. |
| CVE-2020-20913 | Crítica (9.8) | 1.4% | — | 4 abr 2023 | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter. |
| CVE-2022-47042 | Alta (8.8) | 1.0% | — | 26 ene 2023 | MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do. |
| CVE-2022-4640 | Media (5.4) | 0.41% | — | 21 dic 2022 | A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting.… |
| CVE-2022-4375 | Crítica (9.8) | 3.0% | — | 9 dic 2022 | A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql… |
| CVE-2022-4350 | Media (6.1) | 0.41% | — | 8 dic 2022 | A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site… |
| CVE-2022-36599 | Crítica (9.8) | 1.1% | — | 16 ago 2022 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. |
| CVE-2022-36272 | Crítica (9.8) | 1.1% | — | 16 ago 2022 | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter. |
| CVE-2022-31943 | Crítica (9.8) | 1.5% | — | 1 jul 2022 | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability. |
| CVE-2022-30506 | Crítica (9.8) | 2.6% | — | 2 jun 2022 | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file. |
| CVE-2022-29647 | Alta (8.8) | 0.65% | — | 2 jun 2022 | An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do. |
| CVE-2022-30048 | Crítica (9.8) | 1.5% | — | 11 may 2022 | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter. |
| CVE-2022-30047 | Crítica (9.8) | 1.5% | — | 11 may 2022 | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter. |
| CVE-2022-27466 | Crítica (9.8) | 1.6% | — | 2 may 2022 | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do. |
| CVE-2022-27340 | Alta (8.8) | 0.67% | — | 22 abr 2022 | MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data. |