Mingsoft's vulnerability footprint concentrates in a single content-management system product, MCMS, that operates as a web-facing publishing and asset-handling platform. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of web application flaws in deployed systems. The recurring weakness classes—SQL injection, unrestricted file upload, cross-site request forgery, and broader input-handling failures—are characteristic of server-side web application logic and demonstrate consistent, durable patterns in the product's input validation and access-control architecture. Defenders deploying MCMS should treat this vendor's advisories as high-priority, prioritize patching for internet-reachable instances, and focus on the application layer's boundary interactions; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mingsoft over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4375CRITICAL A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the | Dec 9, 2022 | 9.8 | 44 | NO | YES |
CVE-2022-25125CRITICAL MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. | Mar 3, 2022 | 9.8 | 44 | NO | YES |
CVE-2022-22930CRITICAL A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload. | Jan 21, 2022 | 9.8 | 43 | NO | NO |
CVE-2023-50578CRITICAL Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. | Dec 30, 2023 | 9.8 | 38 | NO | YES |
CVE-2022-23898CRITICAL MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. | Mar 3, 2022 | 9.8 | 37 | NO | YES |
CVE-2022-26585CRITICAL Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. | Apr 5, 2022 | 9.8 | 36 | NO | YES |
CVE-2025-56316CRITICAL A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitize | Oct 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-22567HIGH File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. | Feb 5, 2024 | 8.8 | 33 | NO | NO |
CVE-2022-36599CRITICAL Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | Aug 16, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-46384CRITICAL https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new( | Mar 4, 2022 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mingsoft.
Media articles that mention a CVE ID that affects a product developed by Mingsoft — matched by CVE ID, not by vendor name.