CVE-2025-56316: SQL Injection
A SQL injection vulnerability in the contenttitle parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
Other sources
A SQL injection vulnerability in the contenttitle parameter of the /cms/content/list endpoint in MCMS 5.5.0 through 6.0.1 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
— GitHub
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-56316?
CVE-2025-56316 is categorized as a critical severity vulnerability due to its potential for remote code execution via SQL injection.
How do I fix CVE-2025-56316?
To remediate CVE-2025-56316, upgrade your software to version 6.0.2 or later, which addresses the vulnerability.
Which versions of MCMS are affected by CVE-2025-56316?
CVE-2025-56316 affects MCMS version 5.5.0 and version 6.0.1.
What type of vulnerability is CVE-2025-56316?
CVE-2025-56316 is a SQL injection vulnerability that allows attackers to execute arbitrary SQL queries.
Where is the CVE-2025-56316 vulnerability located?
The vulnerability is found in the content_title parameter of the /cms/content/list endpoint in MCMS software.