VYPR
Vendor

Publiccms

Products
1
CVEs
48
Across products
48
Status
Private

Products

1

Recent CVEs

48
View all 48 CVEs →
  • CVE-2022-23389CriFeb 14, 2022
    risk 0.65cvss 9.8epss 0.22

    PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

  • CVE-2025-25361CriMar 6, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.

  • CVE-2023-46990CriNov 20, 2023
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.

  • CVE-2023-34852CriJun 15, 2023
    risk 0.64cvss 9.8epss 0.01

    PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

  • CVE-2020-20915CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.

  • CVE-2020-20914CriApr 4, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.

  • CVE-2021-40881CriSep 15, 2021
    risk 0.64cvss 9.8epss 0.02

    An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.

  • CVE-2018-12914CriJun 27, 2018
    risk 0.64cvss 9.8epss 0.04

    A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.

  • CVE-2025-65836CriDec 1, 2025
    risk 0.59cvss 9.1epss 0.00

    PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

  • CVE-2025-69437HigFeb 27, 2026
    risk 0.57cvss 8.7epss 0.00

    PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system and views it, the embedded…

  • CVE-2025-65840HigDec 1, 2025
    risk 0.57cvss 8.8epss 0.00

    PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

  • CVE-2024-40552HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.

  • CVE-2024-40551HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40550HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40549HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40548HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40546HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40545HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40544HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.

  • CVE-2024-40543HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.00

    PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.