MCMS vulnerable SQL injection via the content_title parameter
Critical severity
GitHub Reviewed
Published
Oct 17, 2025
to the GitHub Advisory Database
•
Updated Oct 21, 2025
Description
Published by the National Vulnerability Database
Oct 17, 2025
Published to the GitHub Advisory Database
Oct 17, 2025
Reviewed
Oct 21, 2025
Last updated
Oct 21, 2025
A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 through 6.0.1 allows remote attackers to execute arbitrary SQL queries via unsanitized input in the FreeMarker template rendering.
References