Vulnerabilities
22 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-31272 | MRCMS 3.1.2 contains an access control vulnerability. MRCMS 3.1.2 contains an access control vulnerability. The save() method in src/main/java/org/marker/mushroom/controller/UserController.java lacks proper authorization validation, enabling direct addition of super administrator accounts without authentication. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2026-29909 | MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials. NVD description · AI analysis pending | 5.3 | <1% | PoC |
| — | |
| CVE-2025-50581 | MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do. MRCMS v3.1.2 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/group/save.do. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2025-4327 | A vulnerability was found in MRCMS 3.1.2. A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Multiple endpoints might be affected. NVD description · AI analysis pending | 5.3 group max | <1% | PoC |
| — | |
| CVE-2025-4293 +1 in the same advisory: …4292 | A vulnerability was found in MRCMS 3.1.3 and classified as problematic. A vulnerability was found in MRCMS 3.1.3 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/group/edit.do of the component Group Edit Page. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NVD description · AI analysis pending | 4.8 | <1% | PoC |
| — | |
| CVE-2025-2193 | A vulnerability has been found in MRCMS 3.1.2 and classified as critical. A vulnerability has been found in MRCMS 3.1.2 and classified as critical. This vulnerability affects the function delete of the file /admin/file/delete.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument path/name leads to path traversal. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. NVD description · AI analysis pending | 5.3 group max | <1% | PoC |
| — | |
| CVE-2025-25768 | MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. MRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.java. This vulnerability allows attackers to execute arbitrary code via a crafted payload. NVD description · AI analysis pending | 5.4 group max | <1% | PoC |
| — | |
| CVE-2024-48177 | MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do. MRCMS 3.1.2 contains a SQL injection vulnerability via the RID parameter in /admin/article/delete.do. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2024-25428 | SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter. SQL Injection vulnerability in MRCMS v3.1.2 allows attackers to run arbitrary system commands via the status parameter. NVD description · AI analysis pending | 6.5 | <1% | PoC |
| — | |
| CVE-2024-24161 +1 in the same advisory: …24160 | MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered. MRCMS 3.0 contains an Arbitrary File Read vulnerability in /admin/file/edit.do as the incoming path parameter is not filtered. NVD description · AI analysis pending | 7.5 group max | <1% | PoC |
| — |