Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 28 Mar 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in mingSoft MCMS 迄 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. |
Fri, 27 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 27 Mar 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in mingSoft MCMS 迄 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. | |
| Title | mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection | |
| First Time appeared |
Mingsoft
Mingsoft mcms |
|
| Weaknesses | CWE-74 CWE-89 |
|
| CPEs | cpe:2.3:a:mingsoft:mcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mingsoft
Mingsoft mcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-03-27T22:16:13.177Z
Reserved: 2026-03-27T07:53:22.716Z
Link: CVE-2026-4954
Updated: 2026-03-27T14:46:32.463Z
Status : Deferred
Published: 2026-03-27T15:17:02.820
Modified: 2026-04-29T01:00:01.613
Link: CVE-2026-4954
No data.
OpenCVE Enrichment
Updated: 2026-03-30T07:01:50Z