CVE-2026-29909: Mrcms
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
MRCMS V3.1.2 contains an unauthenticated directory enumeration vulnerability in the file management module. The /admin/file/list.do endpoint lacks authentication controls and proper input validation, allowing remote attackers to enumerate directory contents on the server without any credentials.
Affected products
- Mrcms Mrcms: version 3.1.2 only
Published 2026-03-30. Last modified 2026-06-17.