Vulnerabilities > Mingsoft > Mcms > 4.6.5

DATE CVE VULNERABILITY TITLE RISK
2023-07-28 CVE-2023-3990 Cross-site Scripting vulnerability in Mingsoft Mcms
A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1.
network
low complexity
mingsoft CWE-79
6.1
2022-12-09 CVE-2022-4375 SQL Injection vulnerability in Mingsoft Mcms
A vulnerability was found in Mingsoft MCMS up to 5.2.9.
network
low complexity
mingsoft CWE-89
critical
9.8
2022-03-04 CVE-2021-46384 Missing Authentication for Critical Function vulnerability in Mingsoft Mcms
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.
network
low complexity
mingsoft CWE-306
7.5
2022-01-26 CVE-2021-46385 SQL Injection vulnerability in Mingsoft Mcms 4.6.5/5.2.4/5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection.
network
low complexity
mingsoft CWE-89
5.0
2022-01-26 CVE-2021-46383 SQL Injection vulnerability in Mingsoft Mcms 4.6.5/5.2.4/5.2.5
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection.
network
low complexity
mingsoft CWE-89
5.0
2022-01-26 CVE-2021-46386 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.
network
low complexity
mingsoft CWE-434
critical
9.8
2018-10-30 CVE-2018-18831 Path Traversal vulnerability in Mingsoft Mcms 4.6.5
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5.
network
low complexity
mingsoft CWE-22
5.0
2018-10-30 CVE-2018-18830 Unrestricted Upload of File with Dangerous Type vulnerability in Mingsoft Mcms 4.6.5
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.
network
low complexity
mingsoft CWE-434
7.5