VendorsMingsoftmcms5.2.5
Vulnerabilities

Mingsoft Mcms 5.2.5

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2022-23898
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
Published 2022-03-03 · Modified
9.8EPSS 0.077
CVE-2022-23899
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.
Published 2022-03-03 · Modified
9.8EPSS 0.011
CVE-2021-46063
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
Published 2022-02-18 · Modified
9.1EPSS 0.027
CVE-2021-46062
MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.
Published 2022-02-18 · Modified
7.1EPSS 0.008