Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mrcms CRITICAL 9.8
CVE-2026-31272

MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks pro…

Mitigation only
Fix from $2,300 2026-04-07
Mrcms MEDIUM 5.3
CVE-2026-29909

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks au…

No fix yet
Fix from $1,600 2026-03-30
Mrcms MEDIUM 5.4
CVE-2025-4326

A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of …

No fix yet
Fix from $1,600 2025-05-06
Mrcms MEDIUM 5.4
CVE-2025-4324

A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the c…

No fix yet
Fix from $1,600 2025-05-06
Mrcms MEDIUM 5.4
CVE-2025-4323

A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the comp…

No fix yet
Fix from $1,600 2025-05-06
Mrcms MEDIUM 5.4
CVE-2025-4292

A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /…

No fix yet
Fix from $1,600 2025-05-05
Mrcms MEDIUM 5.4
CVE-2025-4293

A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group…

No fix yet
Fix from $1,600 2025-05-05
Mrcms MEDIUM 6.1
CVE-2025-2196

A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adm…

No fix yet
Fix from $1,600 2025-03-11
Mrcms MEDIUM 6.1
CVE-2025-2194

A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the c…

No fix yet
Fix from $1,600 2025-03-11
Mrcms MEDIUM 6.1
CVE-2025-2195

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of…

No fix yet
Fix from $1,600 2025-03-11
Mrcms HIGH 8.1
CVE-2025-2193

A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/dele…

No fix yet
Fix from $1,950 2025-03-11
Mrcms MEDIUM 5.4
CVE-2025-25768

MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This v…

No fix yet
Fix from $1,600 2025-02-21
Mrcms HIGH 8.8
CVE-2024-48177

MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.

No fix yet
Fix from $1,950 2024-10-28
Mrcms MEDIUM 6.5
CVE-2024-25428

SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

No fix yet
Fix from $1,600 2024-02-20
Mrcms HIGH 7.5
CVE-2024-24161

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

No fix yet
Fix from $1,950 2024-02-02
Mrcms MEDIUM 5.4
CVE-2024-24160

MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do.

No fix yet
Fix from $1,600 2024-02-02