Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-19355: MingSoft MCMS SQL Injection via Malformed Form Data

CVE-2026-19355 · published 26 days ago
Summary

A security flaw in MingSoft MCMS allows attackers to inject malicious SQL code into the system, potentially allowing them to access sensitive data. This vulnerability affects versions up to 3.0.6. It's essential to update to the latest version to prevent exploitation.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
mingsoft mcms 3.0.0
Original advisory text
MingSoft MCMS ms-mdiy list.do ModelDataImpl.queryDiyFormData sql injection
A vulnerability was determined in MingSoft MCMS up to 3.0.6. This affects the function ModelDataImpl.queryDiyFormData of the file /mdiy/form/data/list.do of the component ms-mdiy. Executing a manipulation of the argument formFields can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Severity
5.5 Medium
CVSS 2.0: 7.5 (NVD)
CVSS 3.1: 7.3 (NVD)
CVSS 4.0: 5.5 (NVD)
Exploitation
EPSS <1%
Type
CWE-74Injection
CWE-89SQL Injection
Timeline
Published9 Aug 2026
Updated30 Aug 2026
First seen9 Aug 2026
Sources
CVE-2026-19355 · MITRE
Monitor software like this
Free during beta