Publiccms
by Publiccms
Source repositories
CVEs (48)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23389 | Cri | 0.65 | 9.8 | 0.22 | Feb 14, 2022 | PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. | ||
| CVE-2025-25361 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2025 | An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file. | ||
| CVE-2023-46990 | Cri | 0.64 | 9.8 | 0.01 | Nov 20, 2023 | Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function. | ||
| CVE-2023-34852 | Cri | 0.64 | 9.8 | 0.01 | Jun 15, 2023 | PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions. | ||
| CVE-2020-20915 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2023 | SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl. | ||
| CVE-2020-20914 | Cri | 0.64 | 9.8 | 0.01 | Apr 4, 2023 | SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. | ||
| CVE-2021-40881 | Cri | 0.64 | 9.8 | 0.02 | Sep 15, 2021 | An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code. | ||
| CVE-2018-12914 | Cri | 0.64 | 9.8 | 0.04 | Jun 27, 2018 | A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI. | ||
| CVE-2025-65836 | Cri | 0.59 | 9.1 | 0.00 | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. | ||
| CVE-2025-69437 | Hig | 0.57 | 8.7 | 0.00 | Feb 27, 2026 | PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded… | ||
| CVE-2025-65840 | Hig | 0.57 | 8.8 | 0.00 | Dec 1, 2025 | PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. | ||
| CVE-2024-40552 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java. | ||
| CVE-2024-40551 | Hig | 0.57 | 8.8 | 0.00 | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-40550 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-40549 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-40548 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-40546 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-40545 | Hig | 0.57 | 8.8 | 0.01 | Jul 12, 2024 | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-40544 | Hig | 0.57 | 8.8 | 0.00 | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit. | ||
| CVE-2024-40543 | Hig | 0.57 | 8.8 | 0.00 | Jul 12, 2024 | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage. |
- risk 0.65cvss 9.8epss 0.22
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.
- risk 0.64cvss 9.8epss 0.01
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
- risk 0.64cvss 9.8epss 0.01
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
- risk 0.64cvss 9.8epss 0.02
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
- risk 0.64cvss 9.8epss 0.04
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.
- risk 0.59cvss 9.1epss 0.00
PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
- risk 0.57cvss 8.7epss 0.00
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded…
- risk 0.57cvss 8.8epss 0.00
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
- risk 0.57cvss 8.8epss 0.01
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
- risk 0.57cvss 8.8epss 0.00
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.01
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.57cvss 8.8epss 0.00
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.
- risk 0.57cvss 8.8epss 0.00
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
Page 1 of 3