Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mingsoft mcms vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-31943
MCMS v5.2.8 exists to contain an arbitrary file upload vulnerability.
Mingsoft Mcms 5.2.8
9.8
CVSSv3
CVE-2022-30506
An arbitrary file upload vulnerability exists in MCMS 5.2.7, allowing an malicious user to execute arbitrary code through a crafted ZIP file.
Mingsoft Mcms 5.2.7
9.8
CVSSv3
CVE-2022-26585
Mingsoft MCMS v5.2.7 exists to contain a SQL injection vulnerability via /cms/content/list.
Mingsoft Mcms 5.2.7
9.8
CVSSv3
CVE-2022-23314
MCMS v5.2.4 exists to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
Mingsoft Mcms 5.2.4
9.8
CVSSv3
CVE-2022-23315
MCMS v5.2.4 exists to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
Mingsoft Mcms 5.2.4
9.8
CVSSv3
CVE-2022-36272
Mingsoft MCMS 5.2.8 exists to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
Mingsoft Mcms 5.2.8
8.8
CVSSv3
CVE-2024-22567
File Upload vulnerability in MCMS 5.3.5 allows malicious users to upload arbitrary files via crafted POST request to /ms/file/upload.do.
Mingsoft Mcms 5.3.5
1 Github repository
8.8
CVSSv3
CVE-2022-29647
An issue exists in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.
Mingsoft Mcms 5.2.7
9.8
CVSSv3
CVE-2023-50578
Mingsoft MCMS v5.2.9 exists to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
Mingsoft Mcms 5.2.9
9.8
CVSSv3
CVE-2018-18830
An issue exists in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then...
Mingsoft Mcms 4.6.5
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3380
CVE-2024-1694
local file inclusion
CVE-2024-5645
CVE-2024-24919
XSS
CVE-2024-36774
CVE-2024-21306
SQL
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »