Mkcms Project maintains a narrowly scoped content-management system whose vulnerabilities, while modest in volume, skew strongly toward critical severity outcomes. The exposure concentrates in the core Mkcms product and recurs through high-impact application-layer weakness classes including SQL injection, cross-site request forgery, and data-handling gaps that are characteristic of CMS platforms exposed to user input. Defenders treating this vendor as a deployed CMS should prioritize patching with attention to the severity profile; live exploitation activity and current CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mkcms Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-22820CRITICAL MKCMS V6.2 has SQL injection via the /ucenter/repass.php name parameter. | Nov 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-22819CRITICAL MKCMS V6.2 has SQL injection via the /ucenter/active.php verify parameter. | Nov 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-22818CRITICAL MKCMS V6.2 has SQL injection via /ucenter/reg.php name parameter. | Nov 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-10707CRITICAL MKCMS V5.0 has SQL injection via the bplay.php play parameter. | Apr 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-11332HIGH MKCMS 5.0 allows remote attackers to take over arbitrary user accounts by posting a username and e-mail address to ucenter/repass.php, which triggers e-mail transmission with the p | Apr 18, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-11078HIGH MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI. | Apr 11, 2019 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mkcms Project.
Media articles that mention a CVE ID that affects a product developed by Mkcms Project — matched by CVE ID, not by vendor name.