Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mingsoft

First CVE: Sep 23, 2018Active for: 8 yearsTotal CVEs: 47
64.7
VTI Score
TOP TARGET

Mingsoft's vulnerability footprint concentrates in a single content-management system product, MCMS, that operates as a web-facing publishing and asset-handling platform. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of web application flaws in deployed systems. The recurring weakness classes—SQL injection, unrestricted file upload, cross-site request forgery, and broader input-handling failures—are characteristic of server-side web application logic and demonstrate consistent, durable patterns in the product's input validation and access-control architecture. Defenders deploying MCMS should treat this vendor's advisories as high-priority, prioritize patching for internet-reachable instances, and focus on the application layer's boundary interactions; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
47
Total CVEs
More Total CVEs than 98% of tracked vendors
6.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.9
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mingsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2018
7 years ago
Most Recent CVE
Feb 18, 2026
156 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-4375CRITICAL
A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the
Dec 9, 20229.844NOYES
CVE-2022-25125CRITICAL
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
Mar 3, 20229.844NOYES
CVE-2022-22930CRITICAL
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.
Jan 21, 20229.843NONO
CVE-2023-50578CRITICAL
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
Dec 30, 20239.838NOYES
CVE-2022-23898CRITICAL
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
Mar 3, 20229.837NOYES
CVE-2022-26585CRITICAL
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
Apr 5, 20229.836NOYES
CVE-2025-56316CRITICAL
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitize
Oct 17, 20259.834NONO
CVE-2024-22567HIGH
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
Feb 5, 20248.833NONO
CVE-2022-36599CRITICAL
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
Aug 16, 20229.832NONO
CVE-2021-46384CRITICAL
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new(
Mar 4, 20229.832NONO
View all 47 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products47 CVEs
11%
30%
60%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network46 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (97.9%)
High1 (2.1%)
Unknown0 (0.0%)
User Interaction
None39 (83.0%)
Unknown0 (0.0%)
Required8 (17.0%)
Privileges Required
Low5 (10.6%)
High1 (2.1%)
None41 (87.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
12.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mingsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mingsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mingsoft's Products

View all 2 CNAs →

Top CWEs