Vulnerabilities > Mingsoft > Mcms

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-22567 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.3.5
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
network
low complexity
mingsoft CWE-434
8.8
2024-01-16 CVE-2023-51282 Code Injection vulnerability in Mingsoft Mcms 5.2.4
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
network
low complexity
mingsoft CWE-94
7.5
2023-12-30 CVE-2023-50578 SQL Injection vulnerability in Mingsoft Mcms 5.2.9
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
network
low complexity
mingsoft CWE-89
critical
9.8
2023-07-28 CVE-2023-3990 Cross-site Scripting vulnerability in Mingsoft Mcms
A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1.
network
low complexity
mingsoft CWE-79
6.1
2023-05-08 CVE-2020-22755 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.0
File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail.
network
low complexity
mingsoft CWE-434
8.8
2023-01-26 CVE-2022-47042 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.2.10/5.2.8/5.2.9
MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.
network
low complexity
mingsoft CWE-434
8.8
2022-12-21 CVE-2022-4640 Improper Enforcement of Message or Data Structure vulnerability in Mingsoft Mcms 5.2.9
A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic.
network
low complexity
mingsoft CWE-707
5.4
2022-12-09 CVE-2022-4375 SQL Injection vulnerability in Mingsoft Mcms
A vulnerability was found in Mingsoft MCMS up to 5.2.9.
network
low complexity
mingsoft CWE-89
critical
9.8
2022-12-08 CVE-2022-4350 Improper Enforcement of Message or Data Structure vulnerability in Mingsoft Mcms 5.2.8
A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8.
network
low complexity
mingsoft CWE-707
6.1
2022-07-01 CVE-2022-31943 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 5.2.8
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
network
low complexity
mingsoft CWE-434
7.5