CVE-2022-22928: Mingsoft Mcms

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

MCMS v5.2.4 was discovered to have a hardcoded shiro-key, allowing attackers to exploit the key and execute arbitrary code.

Affected products

Published 2022-01-21. Last modified 2026-06-17.