CVE-2025-60837
23.10.2025, 19:15
A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in the context of a user's browser via a crafted payload.
| Vendor | Product | Version |
|---|---|---|
| mingsoft | mcms | 𝑥 ≤ 6.0.1 |
𝑥
= Vulnerable software versions