CVE-2025-56316

CRITICAL9.8EPSS 0.16%

MCMS vulnerable SQL injection via the content_title parameter

Published: 10/17/2025Modified: 10/21/2025
Also known as:GHSA-54wc-49qj-5ghj

Description

A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 through 6.0.1 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (4)