Vulnerabilities (CVE)

Filtered by vendor Mrcms Subscribe
Filtered by product Mrcms
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-25765 1 Mrcms 1 Mrcms 2025-03-28 N/A 4.0 MEDIUM
MRCMS v3.1.2 was discovered to contain an arbitrary file write vulnerability via the component /file/save.do.
CVE-2025-25766 1 Mrcms 1 Mrcms 2025-03-28 N/A 4.8 MEDIUM
An arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uploading a crafted .jsp file.
CVE-2024-24161 1 Mrcms 1 Mrcms 2024-11-21 N/A 7.5 HIGH
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.
CVE-2024-24160 1 Mrcms 1 Mrcms 2024-11-21 N/A 5.4 MEDIUM
MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.