Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Publiccms HIGH 8.7
CVE-2025-69437

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the ba…

Fix: after 5.202506.d
Fix from $1,950 2026-02-27
Publiccms CRITICAL 9.8
CVE-2026-3289

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the…

Mitigation only
Fix from $2,300 2026-02-27
Publiccms HIGH 8.1
CVE-2026-1112

A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public…

Fix: after 5.202506.d
Fix from $1,950 2026-01-18
Publiccms HIGH 7.2
CVE-2026-1111

A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/T…

Fix: after 5.202506.d
Fix from $1,950 2026-01-18
Publiccms MEDIUM 5.4
CVE-2025-65837

PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

No fix yet
Fix from $1,600 2025-12-22
Publiccms HIGH 8.8
CVE-2025-65840

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

No fix yet
Fix from $1,950 2025-12-01
Publiccms CRITICAL 9.1
CVE-2025-65836

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

No fix yet
Fix from $2,300 2025-12-01
Publiccms HIGH 7.5
CVE-2025-65838

PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

No fix yet
Fix from $1,950 2025-12-01
Publiccms HIGH 8.2
CVE-2025-57516

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via…

No fix yet
Fix from $1,950 2025-09-29
Publiccms MEDIUM 6.1
CVE-2025-7953

A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processin…

Fix: 5.202506.b+
Fix from $1,600 2025-07-22
Publiccms MEDIUM 6.1
CVE-2025-7949

A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown fu…

Fix: 5.202506.b+
Fix from $1,600 2025-07-22
Publiccms CRITICAL 9.8
CVE-2025-25361

An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi…

No fix yet
Fix from $2,300 2025-03-06
Publiccms MEDIUM 5.4
CVE-2024-11070

A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of t…

No fix yet
Fix from $1,600 2024-11-11
Publiccms HIGH 7.2
CVE-2024-42523

publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData

Fix: after 4.0.202302.e
Fix from $1,950 2024-08-23
Publiccms HIGH 8.8
CVE-2024-40543

PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40544

PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40545

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary c…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40546

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code …

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40548

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40549

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40550

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40551

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary …

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms HIGH 8.8
CVE-2024-40552

PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent…

Fix: after 4.0.202302.e
Fix from $1,950 2024-07-12
Publiccms MEDIUM 6.5
CVE-2024-40547

PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.

Fix: after 4.0.202302.e
Fix from $1,600 2024-07-12
Publiccms HIGH 8.8
CVE-2024-31759

An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.

No fix yet
Fix from $1,950 2024-04-16
Publiccms MEDIUM 5.4
CVE-2023-51252

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html …

No fix yet
Fix from $1,600 2024-01-10
Publiccms CRITICAL 9.8
CVE-2023-46990

Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep…

No fix yet
Fix from $2,300 2023-11-20
Publiccms MEDIUM 6.5
CVE-2023-48204

An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/me…

No fix yet
Fix from $1,600 2023-11-16
Publiccms CRITICAL 9.8
CVE-2023-34852

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

Fix: after 4.0.202302
Fix from $2,300 2023-06-15
Publiccms CRITICAL 9.8
CVE-2020-20914

SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.

No fix yet
Fix from $2,300 2023-04-04