Mcms
Vendor:
First CVE: Sep 23, 2018 · Active for 7 years
47
Total CVEs
More Total CVEs than 97% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 82% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mcms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 23, 2018
7 years ago
Most Recent CVE
Feb 18, 2026
156 days ago
CVE Severity & Scoring
Mcms47 CVEs
11%
30%
60%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.1%)
Network46 (97.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low46 (97.9%)
High1 (2.1%)
Unknown0 (0.0%)
User Interaction
None39 (83.0%)
Unknown0 (0.0%)
Required8 (17.0%)
Privileges Required
Low5 (10.6%)
High1 (2.1%)
None41 (87.2%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-4375CRITICAL A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the | Dec 9, 2022 | 9.8 | 44 | NO | YES |
CVE-2022-25125CRITICAL MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp. | Mar 3, 2022 | 9.8 | 44 | NO | YES |
CVE-2022-22930CRITICAL A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload. | Jan 21, 2022 | 9.8 | 43 | NO | NO |
CVE-2023-50578CRITICAL Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do. | Dec 30, 2023 | 9.8 | 38 | NO | YES |
CVE-2022-23898CRITICAL MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml. | Mar 3, 2022 | 9.8 | 37 | NO | YES |
CVE-2022-26585CRITICAL Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list. | Apr 5, 2022 | 9.8 | 36 | NO | YES |
CVE-2025-56316CRITICAL A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitize | Oct 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2024-22567HIGH File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do. | Feb 5, 2024 | 8.8 | 33 | NO | NO |
CVE-2022-36599CRITICAL Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists. | Aug 16, 2022 | 9.8 | 32 | NO | NO |
CVE-2021-46384CRITICAL https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new( | Mar 4, 2022 | 9.8 | 32 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (47 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
6 CVEs
12.8% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (47 CVEs).
Media Mentions
Signals from CVEs in this product scope (47 CVEs).
Top CNAs Publishing CVEs For Mcms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.1.1 | 1 | 7.2 | 0.4% | 0 | 0 |
| 6.0.1 | 1 | 9.8 | 0.6% | 0 | 0 |
| 5.5.0 | 1 | 9.8 | 0.6% | 0 | 0 |
| 5.4.3 | 1 | 9.8 | 0.7% | 0 | 0 |
| 5.4.1 | 1 | 8.1 | 0.8% | 0 | 0 |
| 5.3.5 | 1 | 8.8 | 17.8% | 0 | 0 |
| 5.2.9 | 3 | 8.0 | 1.2% | 0 | 1 |
| 5.2.8 | 5 | 8.9 | 0.9% | 0 | 0 |
| 5.2.7 | 6 | 9.5 | 2.1% | 0 | 1 |
| 5.2.5 | 4 | 8.9 | 3.1% | 0 | 1 |
| 5.2.4 | 9 | 9.4 | 5.0% | 0 | 1 |
| 5.2.27 | 1 | 9.8 | 1.6% | 0 | 0 |
| 5.2.10 | 1 | 8.8 | 1.0% | 0 | 0 |
| 5.1 | 1 | 9.8 | 1.4% | 0 | 0 |
| 5.0.0 | 1 | 9.8 | 1.1% | 0 | 0 |
| 5.0 | 1 | 8.8 | 0.9% | 0 | 0 |
| 4.7.2 | 1 | 9.8 | 1.4% | 0 | 0 |
| 4.6.5 | 3 | 8.7 | 1.1% | 0 | 0 |