CVE-2019-11078: Mkcms Project Mkcms

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

MKCMS V5.0 has a CSRF vulnerability to add a new admin user via the ucenter/userinfo.php URI.

Affected products

Published 2019-04-11. Last modified 2026-06-17.