Ofcms Project / Ofcms
20 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-10204 | OFCMS JSON Query SysUserController.java query sql injection | MEDIUM | 5.3 | May 31, 2026 |
| CVE-2026-10203 | OFCMS JSON Query SystemParamController.java query sql injection | MEDIUM | 5.3 | May 31, 2026 |
| CVE-2026-10202 | OFCMS JSON Query SystemDictController.java query sql injection | MEDIUM | 5.3 | May 31, 2026 |
| CVE-2026-10193 | OFCMS ComnController ComnController.java query sql injection | MEDIUM | 5.3 | May 31, 2026 |
| CVE-2025-1557 | OFCMS cross-site request forgery | MEDIUM | 5.3 | Feb 22, 2025 |
| CVE-2024-48236 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\… | MEDIUM | 6.5 | Oct 25, 2024 |
| CVE-2024-48235 | An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file. | MEDIUM | 6.5 | Oct 25, 2024 |
| CVE-2024-9411 | OFCMS add.json add cross site scripting | MEDIUM | 5.3 | Oct 1, 2024 |
| CVE-2024-34256 | OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | CRITICAL | 9.8 | May 14, 2024 |
| CVE-2023-51807 | Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition compone… | MEDIUM | 5.4 | Jan 16, 2024 |
| CVE-2023-24760 | An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. | HIGH | 8.8 | Mar 16, 2023 |
| CVE-2022-29653 | OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. | MEDIUM | 6.1 | May 31, 2022 |
| CVE-2022-27961 | A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted paylo… | MEDIUM | 5.4 | Apr 10, 2022 |
| CVE-2022-27960 | Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' per… | MEDIUM | 5.4 | Apr 10, 2022 |
| CVE-2019-9617 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 8.8 | Mar 6, 2019 |
| CVE-2019-9616 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 7.2 | Mar 6, 2019 |
| CVE-2019-9615 | An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java. | HIGH | 7.2 | Mar 6, 2019 |
| CVE-2019-9614 | An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Exec… | HIGH | 8.8 | Mar 6, 2019 |
| CVE-2019-9613 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 7.2 | Mar 6, 2019 |
| CVE-2019-9612 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 8.8 | Mar 6, 2019 |
| CVE-2019-9611 | An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter,… | MEDIUM | 6.5 | Mar 6, 2019 |
| CVE-2019-9610 | An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTempl… | MEDIUM | 4.3 | Mar 6, 2019 |
| CVE-2019-9609 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 8.8 | Mar 6, 2019 |
| CVE-2019-9608 | An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for exam… | HIGH | 8.8 | Mar 6, 2019 |
Showing 1 to 20 of 20 CVEs