ZeroHour

Vulnerabilities

22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-31272
MRCMS 3.1.2 contains an access control vulnerability.

MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, enabling direct addition of super administrator accounts without authentication.

NVD description · AI analysis pending
9.8<1% PoC
  • mrcms mrcms
CVE-2026-29909
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module.

MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.

NVD description · AI analysis pending
5.3<1% PoC
  • mrcms mrcms
CVE-2025-50581
MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.

MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do.

NVD description · AI analysis pending
4.8<1% PoC
  • mrcms mrcms
CVE-2025-4327
+4 in the same advisory: …4325 …4326 …4324 …4323
A vulnerability was found in MRCMS 3.1.2.

A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected.

NVD description · AI analysis pending
5.3
group max
<1% PoC
  • mrcms mrcms
CVE-2025-4293
+1 in the same advisory: …4292
A vulnerability was found in MRCMS 3.1.3 and classified as problematic.

A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group/edit.do of the component Group Edit Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

NVD description · AI analysis pending
4.8<1% PoC
  • mrcms mrcms
CVE-2025-2193
+3 in the same advisory: …2196 …2195 …2194
A vulnerability has been found in MRCMS 3.1.2 and classified as critical.

A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path/name leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3
group max
<1% PoC
  • mrcms mrcms
CVE-2025-25768
+3 in the same advisory: …25767 …25766 …25765
MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java.

MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload.

NVD description · AI analysis pending
5.4
group max
<1% PoC
  • mrcms mrcms
CVE-2024-48177
MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.

MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do.

NVD description · AI analysis pending
8.8<1% PoC
  • mrcms mrcms
CVE-2024-25428
SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter.

NVD description · AI analysis pending
6.5<1% PoC
  • mrcms mrcms
CVE-2024-24161
+1 in the same advisory: …24160
MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered.

NVD description · AI analysis pending
7.5
group max
<1% PoC
  • mrcms mrcms