MingSoft vulnerabilities
3 CVEs tracked
MingSoft MCMS appears in our reports with critical vulnerabilities affecting versions up to 3.0.6. Key events revolve around a SQL injection flaw (CVE-2026-19355) and two information disclosure vulnerabilities (CVE-2026-19356, CVE-2026-19357) within the ms-mdiy component's various functions. These issues enable remote exploitation, particularly through manipulation of the formFields argument. Defenders must urgently monitor network traffic targeting the ms-mdiy component, verify their MCMS version, and prepare an immediate patching strategy.
Azərbaycanca: MingSoft MCMS, bizim hesabatlarda 3.0.6 versiyasına qədər olan sistemlərdə kritik boşluqlar ilə görünür. Əsas hadisələr ms-mdiy komponentinin fərqli funksiyalarında aşkarlanan SQL injection (CVE-2026-19355) və iki məlumat sızması (CVE-2026-19356, CVE-2026-19357) zəiflikləridir. Bu problemlər, xüsusilə formFields parametri üzərindən manipulyasiya ilə uzaqdan hücuma imkan yaradır. Müdafiəçilər dərhal ms-mdiy komponentini hədəf alan şəbəkə trafikini monitorinq etməli, istifadə edilən MCMS versiyasını yoxlayaraq təcili yamaq planı hazırlamalıdır.
This vendor's CVEs3
This hub is built from skopnix's own reporting on MingSoft: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.