Ucms Project / Ucms
28 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-5015 | UCMS cross site scripting | MEDIUM | 6.1 | Sep 17, 2023 |
| CVE-2023-2294 | UCMS Column Configuration saddpost.php cross site scripting | MEDIUM | 6.1 | Apr 26, 2023 |
| CVE-2023-1303 | UCMS System File Management Module fileedit.php unrestricted upload | CRITICAL | 9.8 | Mar 9, 2023 |
| CVE-2022-42234 | There is a file inclusion vulnerability in the template management module in UCMS 1.6 | HIGH | 8.8 | Oct 14, 2022 |
| CVE-2022-38527 | UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page. | MEDIUM | 6.1 | Sep 19, 2022 |
| CVE-2022-38297 | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | CRITICAL | 9.8 | Sep 12, 2022 |
| CVE-2022-35426 | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | CRITICAL | 9.8 | Aug 9, 2022 |
| CVE-2022-28440 | An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | HIGH | 8.8 | Apr 21, 2022 |
| CVE-2022-28444 | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | HIGH | 7.5 | Apr 21, 2022 |
| CVE-2022-28443 | UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | CRITICAL | 9.1 | Apr 21, 2022 |
| CVE-2020-20781 | A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a… | MEDIUM | 5.4 | Sep 29, 2021 |
| CVE-2021-25809 | UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php. | MEDIUM | 5.3 | Jul 23, 2021 |
| CVE-2020-25537 | File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | CRITICAL | 9.8 | Nov 30, 2020 |
| CVE-2020-25483 | An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server. | CRITICAL | 9.8 | Oct 23, 2020 |
| CVE-2020-24981 | An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly acces… | MEDIUM | 5.3 | Sep 4, 2020 |
| CVE-2019-12251 | sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter. | HIGH | 8.8 | May 21, 2019 |
| CVE-2018-16804 | An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request. | MEDIUM | 6.1 | Mar 7, 2019 |
| CVE-2018-20601 | UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action. | MEDIUM | 4.8 | Dec 30, 2018 |
| CVE-2018-20600 | sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action. | MEDIUM | 6.1 | Dec 30, 2018 |
| CVE-2018-20599 | UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. | HIGH | 8.8 | Dec 30, 2018 |
| CVE-2018-20598 | UCMS 1.4.7 has ?do=user_addpost CSRF. | HIGH | 8.8 | Dec 30, 2018 |
| CVE-2018-20597 | UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action. | MEDIUM | 4.8 | Dec 30, 2018 |
| CVE-2018-19437 | UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values tha… | HIGH | 8.8 | Nov 22, 2018 |
| CVE-2018-17320 | An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action. | MEDIUM | 6.1 | Sep 21, 2018 |
| CVE-2018-17037 | user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3. | HIGH | 8.8 | Sep 14, 2018 |
Showing 1 to 25 of 28 CVEs