CVE-2026-4954: mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection
A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4954?
CVE-2026-4954 has a high severity due to its potential for SQL injection, which can lead to unauthorized data access.
How do I fix CVE-2026-4954?
To fix CVE-2026-4954, update the MingSoft MCMS to a version later than 5.5.0 that addresses this vulnerability.
What software versions are affected by CVE-2026-4954?
CVE-2026-4954 affects all versions of MingSoft MCMS up to and including version 5.5.0.
What type of vulnerability is CVE-2026-4954?
CVE-2026-4954 is classified as an SQL injection vulnerability found in the ContentAction.java file.
Where is CVE-2026-4954 located in the software?
CVE-2026-4954 is located in the list function of the net/mingsoft/cms/action/web/ContentAction.java file.