Ofcms

Ofcms Project · 20 CVEs

CVE-2026-10204
MEDIUM

OFCMS JSON Query SysUserController.java query sql injection

May 31, 2026

CVE-2026-10203
MEDIUM

OFCMS JSON Query SystemParamController.java query sql injection

May 31, 2026

CVE-2026-10202
MEDIUM

OFCMS JSON Query SystemDictController.java query sql injection

May 31, 2026

CVE-2026-10193
MEDIUM

OFCMS ComnController ComnController.java query sql injection

May 31, 2026

CVE-2025-1557
MEDIUM

OFCMS cross-site request forgery

Feb 22, 2025

CVE-2024-48236
MEDIUM

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the wri…

Oct 25, 2024

CVE-2024-48235
MEDIUM

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateControlle…

Oct 25, 2024

CVE-2024-9411
MEDIUM

OFCMS add.json add cross site scripting

Oct 1, 2024

CVE-2024-34256
CRITICAL

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

May 14, 2024

CVE-2023-51807
MEDIUM

Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a craft…

Jan 16, 2024

CVE-2023-24760
HIGH

An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserCont…

Mar 16, 2023

CVE-2022-29653
MEDIUM

OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service…

May 31, 2022

CVE-2022-27961
MEDIUM

A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary…

Apr 10, 2022

CVE-2022-27960
MEDIUM

Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to…

Apr 10, 2022

CVE-2019-9617
HIGH

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…

Mar 6, 2019

CVE-2019-9616
HIGH

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…

Mar 6, 2019

CVE-2019-9615
HIGH

An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to Sy…

Mar 6, 2019

CVE-2019-9614
HIGH

An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#ass…

Mar 6, 2019

CVE-2019-9613
HIGH

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…

Mar 6, 2019

CVE-2019-9612
HIGH

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…

Mar 6, 2019

CVE-2019-9611
MEDIUM

An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory tr…

Mar 6, 2019

CVE-2019-9610
MEDIUM

An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ dire…

Mar 6, 2019

CVE-2019-9609
HIGH

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…

Mar 6, 2019

CVE-2019-9608
HIGH

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and…

Mar 6, 2019

Showing 1 to 20 of 20 CVEs