VYPR

ujcms

by Dromara

CVEs (4)

  • CVE-2024-55451MedDec 16, 2024
    risk 0.31cvss 4.8epss 0.00

    A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a maliciously crafted SVG file is viewed…

  • CVE-2024-12483LowDec 12, 2024
    risk 0.27cvss 3.7epss 0.04

    A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The…

  • CVE-2025-2491LowMar 18, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to cross site…

  • CVE-2025-2490LowMar 18, 2025
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upload. The manipulation leads…