Mcms

Vendor:

First CVE: Sep 23, 2018 · Active for 7 years

47
Total CVEs
More Total CVEs than 97% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 82% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2018
7 years ago
Most Recent CVE
Feb 18, 2026
156 days ago

CVE Severity & Scoring

Mcms47 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network46 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (97.9%)
High1 (2.1%)
Unknown0 (0.0%)
User Interaction
None39 (83.0%)
Unknown0 (0.0%)
Required8 (17.0%)
Privileges Required
Low5 (10.6%)
High1 (2.1%)
None41 (87.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (47 CVEs).

47 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the
Dec 9, 20229.844NOYES
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
Mar 3, 20229.844NOYES
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.
Jan 21, 20229.843NONO
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
Dec 30, 20239.838NOYES
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
Mar 3, 20229.837NOYES
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
Apr 5, 20229.836NOYES
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitize
Oct 17, 20259.834NONO
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
Feb 5, 20248.833NONO
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
Aug 16, 20229.832NONO
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new(
Mar 4, 20229.832NONO

Exploit Exposure

Signals from CVEs in this product scope (47 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
12.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (47 CVEs).

Media Mentions

Signals from CVEs in this product scope (47 CVEs).

Top CNAs Publishing CVEs For Mcms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.1.117.20.4%00
6.0.119.80.6%00
5.5.019.80.6%00
5.4.319.80.7%00
5.4.118.10.8%00
5.3.518.817.8%00
5.2.938.01.2%01
5.2.858.90.9%00
5.2.769.52.1%01
5.2.548.93.1%01
5.2.499.45.0%01
5.2.2719.81.6%00
5.2.1018.81.0%00
5.119.81.4%00
5.0.019.81.1%00
5.018.80.9%00
4.7.219.81.4%00
4.6.538.71.1%00