mingsoft CVE Vulnerabilities & Metrics

Focus on mingsoft vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About mingsoft Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with mingsoft. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total mingsoft CVEs: 40
Earliest CVE date: 30 Oct 2018, 06:29 UTC
Latest CVE date: 05 Feb 2024, 20:15 UTC

Latest CVE reference: CVE-2024-22567

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical mingsoft CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.01

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 11
4.0-6.9 9
7.0-8.9 20
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS mingsoft CVEs

These are the five CVEs with the highest CVSS scores for mingsoft, sorted by severity first and recency.

All CVEs for mingsoft

CVE-2024-22567 mingsoft vulnerability CVSS: 0 05 Feb 2024, 20:15 UTC

File Upload vulnerability in MCMS 5.3.5 allows attackers to upload arbitrary files via crafted POST request to /ms/file/upload.do.

CVE-2023-51282 mingsoft vulnerability CVSS: 0 16 Jan 2024, 02:15 UTC

An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

CVE-2023-50578 mingsoft vulnerability CVSS: 0 30 Dec 2023, 16:15 UTC

Mingsoft MCMS v5.2.9 was discovered to contain a SQL injection vulnerability via the categoryType parameter at /content/list.do.

CVE-2023-3990 mingsoft vulnerability CVSS: 4.0 28 Jul 2023, 07:15 UTC

A vulnerability classified as problematic has been found in Mingsoft MCMS up to 5.3.1. This affects an unknown part of the file search.do of the component HTTP POST Request Handler. The manipulation of the argument style leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-235611.

CVE-2020-22755 mingsoft vulnerability CVSS: 0 08 May 2023, 14:15 UTC

File upload vulnerability in MCMS 5.0 allows attackers to execute arbitrary code via a crafted thumbnail. A different vulnerability than CVE-2022-31943.

CVE-2020-20913 mingsoft vulnerability CVSS: 0 04 Apr 2023, 15:15 UTC

SQL Injection vulnerability found in Ming-Soft MCMS v.4.7.2 allows a remote attacker to execute arbitrary code via basic_title parameter.

CVE-2022-47042 mingsoft vulnerability CVSS: 0 26 Jan 2023, 21:18 UTC

MCMS v5.2.10 and below was discovered to contain an arbitrary file write vulnerability via the component ms/template/writeFileContent.do.

CVE-2022-4640 mingsoft vulnerability CVSS: 0 21 Dec 2022, 22:15 UTC

A vulnerability has been found in Mingsoft MCMS 5.2.9 and classified as problematic. Affected by this vulnerability is the function save of the component Article Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216499.

CVE-2022-4375 mingsoft vulnerability CVSS: 0 09 Dec 2022, 08:15 UTC

A vulnerability was found in Mingsoft MCMS up to 5.2.9. It has been classified as critical. Affected is an unknown function of the file /cms/category/list. The manipulation of the argument sqlWhere leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 5.2.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-215196.

CVE-2022-4350 mingsoft vulnerability CVSS: 0 08 Dec 2022, 10:15 UTC

A vulnerability, which was classified as problematic, was found in Mingsoft MCMS 5.2.8. Affected is an unknown function of the file search.do. The manipulation of the argument content_title leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-215112.

CVE-2022-36599 mingsoft vulnerability CVSS: 0 16 Aug 2022, 13:15 UTC

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/model/delete URI via models Lists.

CVE-2022-36272 mingsoft vulnerability CVSS: 0 16 Aug 2022, 13:15 UTC

Mingsoft MCMS 5.2.8 was discovered to contain a SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameter.

CVE-2022-31943 mingsoft vulnerability CVSS: 7.5 01 Jul 2022, 21:15 UTC

MCMS v5.2.8 was discovered to contain an arbitrary file upload vulnerability.

CVE-2022-30506 mingsoft vulnerability CVSS: 7.5 02 Jun 2022, 14:15 UTC

An arbitrary file upload vulnerability was discovered in MCMS 5.2.7, allowing an attacker to execute arbitrary code through a crafted ZIP file.

CVE-2022-29647 mingsoft vulnerability CVSS: 6.8 02 Jun 2022, 14:15 UTC

An issue was discovered in MCMS 5.2.7. There is a CSRF vulnerability that can add an administrator account via ms/basic/manager/save.do.

CVE-2022-30048 mingsoft vulnerability CVSS: 7.5 11 May 2022, 18:15 UTC

Mingsoft MCMS 5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/list URI via orderBy parameter.

CVE-2022-30047 mingsoft vulnerability CVSS: 7.5 11 May 2022, 18:15 UTC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability in /mdiy/dict/listExcludeApp URI via orderBy parameter.

CVE-2022-27466 mingsoft vulnerability CVSS: 7.5 02 May 2022, 14:15 UTC

MCMS v5.2.27 was discovered to contain a SQL injection vulnerability in the orderBy parameter at /dict/list.do.

CVE-2022-27340 mingsoft vulnerability CVSS: 6.8 22 Apr 2022, 20:15 UTC

MCMS v5.2.7 contains a Cross-Site Request Forgery (CSRF) via /role/saveOrUpdateRole.do. This vulnerability allows attackers to escalate privileges and modify data.

CVE-2022-26585 mingsoft vulnerability CVSS: 7.5 05 Apr 2022, 01:15 UTC

Mingsoft MCMS v5.2.7 was discovered to contain a SQL injection vulnerability via /cms/content/list.

CVE-2021-46384 mingsoft vulnerability CVSS: 7.5 04 Mar 2022, 22:15 UTC

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: RCE. The impact is: execute arbitrary code (remote). The attack vector is: ${"freemarker.template.utility.Execute"?new()("calc")}. ¶¶ MCMS has a pre-auth RCE vulnerability through which allows unauthenticated attacker with network access via http to compromise MCMS. Successful attacks of this vulnerability can result in takeover of MCMS.

CVE-2022-25125 mingsoft vulnerability CVSS: 7.5 03 Mar 2022, 19:15 UTC

MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via search.do in the file /mdiy/dict/listExcludeApp.

CVE-2022-23899 mingsoft vulnerability CVSS: 7.5 03 Mar 2022, 19:15 UTC

MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via search.do in the file /web/MCmsAction.java.

CVE-2022-23898 mingsoft vulnerability CVSS: 7.5 03 Mar 2022, 19:15 UTC

MCMS v5.2.5 was discovered to contain a SQL injection vulnerability via the categoryId parameter in the file IContentDao.xml.

CVE-2021-46063 mingsoft vulnerability CVSS: 6.4 18 Feb 2022, 20:15 UTC

MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.

CVE-2021-46062 mingsoft vulnerability CVSS: 5.8 18 Feb 2022, 20:15 UTC

MCMS v5.2.5 was discovered to contain an arbitrary file deletion vulnerability via the component oldFileName.

CVE-2021-46037 mingsoft vulnerability CVSS: 5.5 18 Feb 2022, 19:15 UTC

MCMS v5.2.4 was discovered to contain an arbitrary file deletion vulnerability via the component /template/unzip.do.

CVE-2021-46036 mingsoft vulnerability CVSS: 7.5 18 Feb 2022, 19:15 UTC

An arbitrary file upload vulnerability in the component /ms/file/uploadTemplate.do of MCMS v5.2.4 allows attackers to execute arbitrary code.

CVE-2021-44868 mingsoft vulnerability CVSS: 7.5 17 Feb 2022, 16:15 UTC

A problem was found in ming-soft MCMS v5.1. There is a sql injection vulnerability in /ms/cms/content/list.do

CVE-2021-46385 mingsoft vulnerability CVSS: 5.0 26 Jan 2022, 19:15 UTC

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.FormDataAction#queryData. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

CVE-2021-46386 mingsoft vulnerability CVSS: 7.5 26 Jan 2022, 17:15 UTC

File upload vulnerability in mingSoft MCMS through 5.2.5, allows remote attackers to execute arbitrary code via a crafted jspx webshell to net.mingsoft.basic.action.web.FileAction#upload.

CVE-2021-46383 mingsoft vulnerability CVSS: 5.0 26 Jan 2022, 17:15 UTC

https://gitee.com/mingSoft/MCMS MCMS <=5.2.5 is affected by: SQL Injection. The impact is: obtain sensitive information (remote). The component is: net.mingsoft.mdiy.action.web.DictAction#list. The attack vector is: 0 or sleep(3). ¶¶ MCMS has a sql injection vulnerability through which attacker can get sensitive information from the database.

CVE-2022-23315 mingsoft vulnerability CVSS: 7.5 21 Jan 2022, 00:15 UTC

MCMS v5.2.4 was discovered to contain an arbitrary file upload vulnerability via the component /ms/template/writeFileContent.do.

CVE-2022-23314 mingsoft vulnerability CVSS: 7.5 21 Jan 2022, 00:15 UTC

MCMS v5.2.4 was discovered to contain a SQL injection vulnerability via /ms/mdiy/model/importJson.do.

CVE-2022-22930 mingsoft vulnerability CVSS: 7.5 21 Jan 2022, 00:15 UTC

A remote code execution (RCE) vulnerability in the Template Management function of MCMS v5.2.4 allows attackers to execute arbitrary code via a crafted payload.

CVE-2022-22929 mingsoft vulnerability CVSS: 7.5 21 Jan 2022, 00:15 UTC

MCMS v5.2.4 was discovered to have an arbitrary file upload vulnerability in the New Template module, which allows attackers to execute arbitrary code via a crafted ZIP file.

CVE-2022-22928 mingsoft vulnerability CVSS: 7.5 21 Jan 2022, 00:15 UTC

MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

CVE-2020-23262 mingsoft vulnerability CVSS: 7.5 26 Jan 2021, 18:15 UTC

An issue was discovered in ming-soft MCMS v5.0, where a malicious user can exploit SQL injection without logging in through /mcms/view.do.

CVE-2018-18831 mingsoft vulnerability CVSS: 5.0 30 Oct 2018, 06:29 UTC

An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Traversal in the url parameter.

CVE-2018-18830 mingsoft vulnerability CVSS: 7.5 30 Oct 2018, 06:29 UTC

An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In the name parameter, change the suffix to jsp. In the response, the server returns the storage path of the file, which can be accessed to execute arbitrary JSP code.