VYPR

Publiccms

by Publiccms

Source repositories

CVEs (48)

  • CVE-2024-31759HigApr 16, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.

  • CVE-2018-11500HigMay 26, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.

  • CVE-2025-57516HigSep 29, 2025
    risk 0.53cvss 8.2epss 0.01

    OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.

  • CVE-2025-65838HigDec 1, 2025
    risk 0.49cvss 7.5epss 0.00

    PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

  • CVE-2024-42523HigAug 23, 2024
    risk 0.47cvss 7.2epss 0.01

    publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

  • CVE-2026-8738MedMay 17, 2026
    risk 0.42cvss 6.5epss 0.00

    A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.j…

  • CVE-2024-40547MedJul 12, 2024
    risk 0.42cvss 6.5epss 0.00

    PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.

  • CVE-2023-48204MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.01

    An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.

  • CVE-2018-12494MedJun 15, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.

  • CVE-2018-12493MedJun 15, 2018
    risk 0.42cvss 6.5epss 0.02

    An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/list.html?path=../ URI.

  • CVE-2026-3289MedFeb 27, 2026
    risk 0.41cvss 6.3epss 0.01

    A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack can be executed remotely.…

  • CVE-2026-1112MedJan 18, 2026
    risk 0.35cvss 5.4epss 0.00

    A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deletion Endpoint. Performing a manipulation…

  • CVE-2025-65837MedDec 22, 2025
    risk 0.35cvss 5.4epss 0.00

    PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

  • CVE-2023-51252MedJan 10, 2024
    risk 0.35cvss 5.4epss 0.00

    PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.

  • CVE-2020-21333MedJul 9, 2021
    risk 0.35cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.

  • CVE-2018-17368MedSep 23, 2018
    risk 0.35cvss 5.3epss 0.01

    An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.

  • CVE-2026-1111MedJan 18, 2026
    risk 0.31cvss 4.7epss 0.01

    A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/TaskTemplateAdminController.java of the component Task Template Management Handler. Such manipulation of the argument path leads to…

  • CVE-2024-46410MedOct 8, 2024
    risk 0.31cvss 4.8epss 0.00

    PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature

  • CVE-2018-18927MedNov 4, 2018
    risk 0.31cvss 4.8epss 0.01

    An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.

  • CVE-2024-2911MedMar 26, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and…