Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-31272 MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks pro… Mrcms Mitigation only Fix from $2,3002026-04-07 MEDIUM 5.3 CVE-2026-29909 MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks au… Mrcms No fix yet Fix from $1,6002026-03-30 MEDIUM 5.4 CVE-2025-4326 A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects some unknown processing of the file /admin/chip/add.do of … Mrcms No fix yet Fix from $1,6002025-05-06 MEDIUM 5.4 CVE-2025-4324 A vulnerability, which was classified as problematic, was found in MRCMS 3.1.2. This affects an unknown part of the file /admin/link/edit.do of the c… Mrcms No fix yet Fix from $1,6002025-05-06 MEDIUM 5.4 CVE-2025-4323 A vulnerability, which was classified as problematic, has been found in MRCMS 3.1.2. Affected by this issue is some unknown functionality of the comp… Mrcms No fix yet Fix from $1,6002025-05-06 MEDIUM 5.4 CVE-2025-4292 A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /… Mrcms No fix yet Fix from $1,6002025-05-05 MEDIUM 5.4 CVE-2025-4293 A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group… Mrcms No fix yet Fix from $1,6002025-05-05 MEDIUM 6.1 CVE-2025-2196 A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /adm… Mrcms No fix yet Fix from $1,6002025-03-11 MEDIUM 6.1 CVE-2025-2194 A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the c… Mrcms No fix yet Fix from $1,6002025-03-11 MEDIUM 6.1 CVE-2025-2195 A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of… Mrcms No fix yet Fix from $1,6002025-03-11 HIGH 8.1 CVE-2025-2193 A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/dele… Mrcms No fix yet Fix from $1,9502025-03-11 MEDIUM 5.4 CVE-2025-25768 MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This v… Mrcms No fix yet Fix from $1,6002025-02-21 HIGH 8.8 CVE-2024-48177 MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do. Mrcms No fix yet Fix from $1,9502024-10-28 MEDIUM 6.5 CVE-2024-25428 SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter. Mrcms No fix yet Fix from $1,6002024-02-20 HIGH 7.5 CVE-2024-24161 MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered. Mrcms No fix yet Fix from $1,9502024-02-02 MEDIUM 5.4 CVE-2024-24160 MRCMS 3.0 contains a Cross-Site Scripting (XSS) vulnerability via /admin/system/saveinfo.do. Mrcms No fix yet Fix from $1,6002024-02-02