MingSoft records
48 published records for vendor mingsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 16
- With a fix record
- 22.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')17
- CWE-434 Unrestricted Upload of File with Dangerous Type12
- CWE-707 Improper Neutralization3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
48 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2022-22930No exploit | A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code vimingsoft · mcms | Critical9.8 | — | 23.7% | Jan 20, 2022 |
41Plan | CVE-2022-23898Proof of concept | MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.mingsoft · mcms · CWE-89 | Critical9.8 | — | 7.7% | Mar 3, 2022 |
41Plan | CVE-2022-25125Proof of concept | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.mingsoft · mcms · CWE-89 | Critical9.8 | — | 7.0% | Mar 3, 2022 |
41Plan | CVE-2022-26585Proof of concept | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.mingsoft · mcms · CWE-89 | Critical9.8 | — | 5.5% | Apr 4, 2022 |
40Plan | CVE-2024-22567No exploit | File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.mingsoft · mcms · CWE-434 | High8.8 | — | 17.8% | Feb 5, 2024 |
40Plan | CVE-2021-46036No exploit | An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary codemingsoft · mcms · CWE-434 | Critical9.8 | — | 3.7% | Feb 18, 2022 |
40Plan | CVE-2021-46386No exploit | File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to nmingsoft · mcms · CWE-434 | Critical9.8 | — | 3.1% | Jan 26, 2022 |
40Plan | CVE-2022-4375Proof of concept | Mingsoft MCMS list sql injectionmingsoft · mcms · CWE-707 | Critical9.8 | — | 3.0% | Dec 9, 2022 |
40Plan | CVE-2022-22929No exploit | MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbimingsoft · mcms · CWE-434 | Critical9.8 | — | 2.6% | Jan 20, 2022 |
40Plan | CVE-2022-30506No exploit | An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP fimingsoft · mcms · CWE-434 | Critical9.8 | — | 2.6% | Jun 2, 2022 |
40Plan | CVE-2022-22928No exploit | MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.mingsoft · mcms · CWE-798 | Critical9.8 | — | 2.5% | Jan 20, 2022 |
40Plan | CVE-2023-50578Proof of concept | Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.mingsoft · mcms · CWE-89 | Critical9.8 | — | 2.2% | Dec 30, 2023 |
40Plan | CVE-2021-46384No exploit | https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.mingsoft · mcms · CWE-306 | Critical9.8 | — | 2.2% | Mar 4, 2022 |
40Plan | CVE-2022-23315No exploit | MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.mingsoft · mcms · CWE-434 | Critical9.8 | — | 1.8% | Jan 20, 2022 |
39Monitor | CVE-2022-27466No exploit | MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.6% | May 2, 2022 |
39Monitor | CVE-2022-23314No exploit | MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.6% | Jan 20, 2022 |
39Monitor | CVE-2022-31943No exploit | MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.mingsoft · mcms · CWE-434 | Critical9.8 | — | 1.5% | Jul 1, 2022 |
39Monitor | CVE-2022-30047No exploit | Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.4% | May 11, 2022 |
39Monitor | CVE-2022-30048No exploit | Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.4% | May 11, 2022 |
39Monitor | CVE-2020-20913No exploit | SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.4% | Apr 4, 2023 |
39Monitor | CVE-2021-44868No exploit | A problem was found in ming-soft MCMS v5.1.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.4% | Feb 17, 2022 |
39Monitor | CVE-2018-18830No exploit | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.mingsoft · mcms · CWE-434 | Critical9.8 | — | 1.2% | Oct 30, 2018 |
39Monitor | CVE-2020-23262No exploit | An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.1% | Jan 26, 2021 |
39Monitor | CVE-2022-36272No exploit | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.1% | Aug 16, 2022 |
39Monitor | CVE-2022-36599No exploit | Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.mingsoft · mcms · CWE-89 | Critical9.8 | — | 1.1% | Aug 16, 2022 |
- CVE-2022-2293046Plan
A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code vi
CriticalCVSS 9.8No exploitEPSS 24%mingsoft · mcmsJan 20, 2022
- CVE-2022-2389841Plan
MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.
CriticalCVSS 9.8Proof of conceptEPSS 8%mingsoft · mcmsMar 3, 2022
- CVE-2022-2512541Plan
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.
CriticalCVSS 9.8Proof of conceptEPSS 7%mingsoft · mcmsMar 3, 2022
- CVE-2022-2658541Plan
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.
CriticalCVSS 9.8Proof of conceptEPSS 5%mingsoft · mcmsApr 4, 2022
- CVE-2024-2256740Plan
File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.
HighCVSS 8.8No exploitEPSS 18%mingsoft · mcmsFeb 5, 2024
- CVE-2021-4603640Plan
An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code
CriticalCVSS 9.8No exploitEPSS 4%mingsoft · mcmsFeb 18, 2022
- CVE-2021-4638640Plan
File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to n
CriticalCVSS 9.8No exploitEPSS 3%mingsoft · mcmsJan 26, 2022
- CVE-2022-437540Plan
Mingsoft MCMS list sql injection
CriticalCVSS 9.8Proof of conceptEPSS 3%mingsoft · mcmsDec 9, 2022
- CVE-2022-2292940Plan
MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbi
CriticalCVSS 9.8No exploitEPSS 3%mingsoft · mcmsJan 20, 2022
- CVE-2022-3050640Plan
An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP fi
CriticalCVSS 9.8No exploitEPSS 3%mingsoft · mcmsJun 2, 2022
- CVE-2022-2292840Plan
MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 3%mingsoft · mcmsJan 20, 2022
- CVE-2023-5057840Plan
Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.
CriticalCVSS 9.8Proof of conceptEPSS 2%mingsoft · mcmsDec 30, 2023
- CVE-2021-4638440Plan
https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE.
CriticalCVSS 9.8No exploitEPSS 2%mingsoft · mcmsMar 4, 2022
- CVE-2022-2331540Plan
MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.
CriticalCVSS 9.8No exploitEPSS 2%mingsoft · mcmsJan 20, 2022
- CVE-2022-2746639Monitor
MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.
CriticalCVSS 9.8No exploitEPSS 2%mingsoft · mcmsMay 2, 2022
- CVE-2022-2331439Monitor
MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.
CriticalCVSS 9.8No exploitEPSS 2%mingsoft · mcmsJan 20, 2022
- CVE-2022-3194339Monitor
MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.
CriticalCVSS 9.8No exploitEPSS 2%mingsoft · mcmsJul 1, 2022
- CVE-2022-3004739Monitor
Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsMay 11, 2022
- CVE-2022-3004839Monitor
Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsMay 11, 2022
- CVE-2020-2091339Monitor
SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsApr 4, 2023
- CVE-2021-4486839Monitor
A problem was found in ming-soft MCMS v5.1.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsFeb 17, 2022
- CVE-2018-1883039Monitor
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsOct 30, 2018
- CVE-2020-2326239Monitor
An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsJan 26, 2021
- CVE-2022-3627239Monitor
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsAug 16, 2022
- CVE-2022-3659939Monitor
Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.
CriticalCVSS 9.8No exploitEPSS 1%mingsoft · mcmsAug 16, 2022