Ofcms
Ofcms Project · 20 CVEs
OFCMS JSON Query SysUserController.java query sql injection
May 31, 2026
OFCMS JSON Query SystemParamController.java query sql injection
May 31, 2026
OFCMS JSON Query SystemDictController.java query sql injection
May 31, 2026
OFCMS ComnController ComnController.java query sql injection
May 31, 2026
OFCMS cross-site request forgery
Feb 22, 2025
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the wri…
Oct 25, 2024
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateControlle…
Oct 25, 2024
OFCMS add.json add cross site scripting
Oct 1, 2024
OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.
May 14, 2024
Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a craft…
Jan 16, 2024
An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserCont…
Mar 16, 2023
OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service…
May 31, 2022
A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary…
Apr 10, 2022
Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to…
Apr 10, 2022
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to Sy…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#ass…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory tr…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ dire…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…
Mar 6, 2019
An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…
Mar 6, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-10204 | OFCMS JSON Query SysUserController.java query sql injection | MEDIUM | 0.19% | May 31, 2026 |
| CVE-2026-10203 | OFCMS JSON Query SystemParamController.java query sql injection | MEDIUM | 0.20% | May 31, 2026 |
| CVE-2026-10202 | OFCMS JSON Query SystemDictController.java query sql injection | MEDIUM | 0.19% | May 31, 2026 |
| CVE-2026-10193 | OFCMS ComnController ComnController.java query sql injection | MEDIUM | 0.20% | May 31, 2026 |
| CVE-2025-1557 | OFCMS cross-site request forgery | MEDIUM | 0.29% | Feb 22, 2025 |
| CVE-2024-48236 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\… | MEDIUM | 0.73% | Oct 25, 2024 |
| CVE-2024-48235 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. | MEDIUM | 0.73% | Oct 25, 2024 |
| CVE-2024-9411 | OFCMS add.json add cross site scripting | MEDIUM | 0.37% | Oct 1, 2024 |
| CVE-2024-34256 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | CRITICAL | 0.65% | May 14, 2024 |
| CVE-2023-51807 | Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition compone… | MEDIUM | 0.45% | Jan 16, 2024 |
| CVE-2023-24760 | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. | HIGH | 0.84% | Mar 16, 2023 |
| CVE-2022-29653 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. | MEDIUM | 0.57% | May 31, 2022 |
| CVE-2022-27961 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylo… | MEDIUM | 0.44% | Apr 10, 2022 |
| CVE-2022-27960 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' per… | MEDIUM | 0.47% | Apr 10, 2022 |
| CVE-2019-9617 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 2.75% | Mar 6, 2019 |
| CVE-2019-9616 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 2.71% | Mar 6, 2019 |
| CVE-2019-9615 | An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. | HIGH | 1.30% | Mar 6, 2019 |
| CVE-2019-9614 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Exec… | HIGH | 2.57% | Mar 6, 2019 |
| CVE-2019-9613 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 2.71% | Mar 6, 2019 |
| CVE-2019-9612 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 2.70% | Mar 6, 2019 |
| CVE-2019-9611 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter,… | MEDIUM | 1.44% | Mar 6, 2019 |
| CVE-2019-9610 | An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTempl… | MEDIUM | 1.36% | Mar 6, 2019 |
| CVE-2019-9609 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 2.70% | Mar 6, 2019 |
| CVE-2019-9608 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 2.70% | Mar 6, 2019 |
Showing 1 to 20 of 20 CVEs