Technology · Maven
net.mingsoft:ms-mcms (Maven) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 39 vulnerabilities in net.mingsoft:ms-mcms (Maven): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-2666, was published on 18 February 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
Latest net.mingsoft:ms-mcms (Maven) vulnerabilities
- CVE-2026-2666: mingSoft MCMS does not properly restrict file uploadslowCVSS 3.1EPSS 0.5%
- CVE-2025-60837: mingSoft MCMS reflected XSS in search.domediumCVSS 6.1EPSS 0.2%
- CVE-2025-56316: MCMS vulnerable SQL injection via the content_title parameterlowCVSS 3.1EPSS 0.6%
- CVE-2025-29287: MCMS allows arbitrary file uploads in the ueditor componentlowCVSS 3.1EPSS 0.8%
- CVE-2024-22567: mingSoft MCMS File Upload vulnerabilitylowCVSS 3.1EPSS 17.8%
- CVE-2023-51282: Code injection in mingSoft MCMSlowCVSS 3.1EPSS 1.1%
- CVE-2023-50578: Mingsoft MCMS SQL injectionlowCVSS 3.1EPSS 2.2%
- CVE-2023-3990: Cross-site Scripting in Mingsoft MCMSlowCVSS 3EPSS 1.4%
- CVE-2020-22755: MCMS vulnerable to arbitrary code execution via crafted thumbnaillowCVSS 3.1EPSS 0.9%
- CVE-2020-20913: Ming-Soft MCMS vulnerable to SQL injectionlowCVSS 3.1EPSS 1.4%
- CVE-2022-47042: Arbitrary file write in net.mingsoft:ms-mcmslowCVSS 3.1EPSS 1.0%
- CVE-2022-4640: Mingsoft MCMS Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.4%
- CVE-2022-4375: Mingsoft MCMS vulnerable to SQL InjectionlowCVSS 3.1EPSS 3.0%
- CVE-2022-4350: Mingsoft MCMS vulnerable to Cross-site ScriptinginfoEPSS 0.4%
- CVE-2022-36272: Mingsoft MCMS SQL injection vulnerability in /mdiy/page/verify URI via fieldName parameterlowCVSS 3.1EPSS 1.1%
- CVE-2022-36599: Mingsoft MCMS SQL injection vulnerability in /mdiy/model/delete URI via models ListlowCVSS 3.1EPSS 1.1%
- CVE-2022-31943: Unrestricted Upload of File with Dangerous Type in MCMSlowCVSS 3.1EPSS 1.5%
- CVE-2022-30506: Code injection in MCMSlowCVSS 3.1EPSS 2.6%
- CVE-2022-29647: Cross Site Request Forgery in Mingsoft MCMSlowCVSS 3.1EPSS 0.7%
- CVE-2018-17366: Mingsoft MCMS CSRF vulnerabilitylowCVSS 3EPSS 0.6%
- CVE-2022-27340: Cross Site Request Forgery in Mingsoft MCMSlowCVSS 3.1EPSS 0.7%
- CVE-2022-26585: SQL injection in net.mingsoft:ms-mcmsinfoEPSS 5.5%
- CVE-2021-46384: Remote code execution in net.mingsoft:ms-mcmslowCVSS 3.1EPSS 2.2%
- CVE-2022-23899: SQL injection in net.mingsoft:ms-mcmslowCVSS 3.1EPSS 1.1%
- CVE-2022-23898: SQL injection in net.mingsoft:ms-mcmslowCVSS 3.1EPSS 7.7%
Most severe net.mingsoft:ms-mcms (Maven) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-60837: mingSoft MCMS reflected XSS in search.domediumCVSS 6.1EPSS 0.2%
- CVE-2022-22930: RCE in Mingsoft MCMSlowCVSS 3.1EPSS 23.7%
- CVE-2024-22567: mingSoft MCMS File Upload vulnerabilitylowCVSS 3.1EPSS 17.8%
- CVE-2022-23898: SQL injection in net.mingsoft:ms-mcmslowCVSS 3.1EPSS 7.7%
- CVE-2021-46036: File upload leading to RCE in MCMSlowCVSS 3.1EPSS 3.7%
- CVE-2021-46386: Mingsoft MCMS vulnerable to Remote Code Execution via file upload.lowCVSS 3.1EPSS 3.1%
- CVE-2022-4375: Mingsoft MCMS vulnerable to SQL InjectionlowCVSS 3.1EPSS 3.0%
- CVE-2021-46063: Server Side Template Injection in MCMSlowCVSS 3.1EPSS 2.7%
- CVE-2022-22929: Arbitrary File Upload in Mingsoft MCMSlowCVSS 3.1EPSS 2.6%
- CVE-2022-30506: Code injection in MCMSlowCVSS 3.1EPSS 2.6%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/net-mingsoft-ms-mcms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "net.mingsoft:ms-mcms (Maven) vulnerabilities", https://junglewise.ai/threats/technologies/net-mingsoft-ms-mcms, 27 September 2026.