VendorsMingsoftmcmsall versions
Vulnerabilities

Mingsoft Mcms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

47CVEs
CVE-2026-2666
mingSoft MCMS Template Archive uploadTemplate.do unrestricted upload
Published 2026-02-18 · Analyzed
7.2EPSS 0.006
CVE-2021-46062
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
Published 2022-02-18 · Modified
7.1EPSS 0.008
CVE-2025-60838
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.
Published 2025-10-10 · Modified
6.5EPSS 0.003
CVE-2023-3990
Mingsoft MCMS HTTP POST Request search.do cross site scripting
Published 2023-07-28 · Modified
6.1EPSS 0.014
CVE-2022-4350
Mingsoft MCMS search.do cross site scripting
Published 2022-12-08 · Modified
6.1EPSS 0.004
CVE-2025-60837
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.
Published 2025-10-23 · Modified
6.1EPSS 0.002
CVE-2022-4640
Mingsoft MCMS Article save cross site scripting
Published 2022-12-21 · Modified
5.4EPSS 0.004
← Prev2 / 2