Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mrcms

First CVE: Feb 2, 2024Active for: 2 yearsTotal CVEs: 22
17.1
VTI Score
Low

Mrcms is a narrowly scoped content management system with a concentrated vulnerability footprint in its core product. The vendor's disclosures cluster around input-handling and code-generation weaknesses that are characteristic of web applications: cross-site scripting, code injection, command injection, SQL injection, and cross-site request forgery recur across the platform's attack surface. These weakness classes reflect common risks in template rendering, dynamic code execution, and database interaction patterns endemic to content management systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
7.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mrcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 2, 2024
2 years ago
Most Recent CVE
Apr 7, 2026
108 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-31272CRITICAL
MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, e
Apr 7, 20269.830NONO
CVE-2025-2193HIGH
A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.mark
Mar 11, 20258.123NONO
CVE-2024-48177HIGH
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.
Oct 28, 20248.823NONO
CVE-2024-24161HIGH
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
Feb 2, 20247.521NONO
CVE-2026-29909MEDIUM
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and prope
Mar 30, 20265.319NONO
CVE-2025-2195MEDIUM
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushr
Mar 11, 20256.119NONO
CVE-2025-2194MEDIUM
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the component org.marker.mushroom.co
Mar 11, 20256.119NONO
CVE-2024-25428MEDIUM
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.
Feb 20, 20246.519NONO
CVE-2025-4326MEDIUM
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of the component Add Fragment Page
May 6, 20255.418NONO
CVE-2025-4323MEDIUM
A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the component Edit Article Page. The ma
May 6, 20255.418NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
77%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (4.5%)
Network20 (90.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (4.5%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None10 (45.5%)
Unknown0 (0.0%)
Required12 (54.5%)
Privileges Required
Low8 (36.4%)
High2 (9.1%)
None12 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mrcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mrcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mrcms's Products

View all 2 CNAs →

Top CWEs