Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Publiccms CRITICAL 9.8
CVE-2026-3289

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the…

Mitigation only
Fix from $2,300 2026-02-27
Publiccms MEDIUM 5.4
CVE-2025-65837

PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

No fix yet
Fix from $1,600 2025-12-22
Publiccms HIGH 8.8
CVE-2025-65840

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

No fix yet
Fix from $1,950 2025-12-01
Publiccms CRITICAL 9.1
CVE-2025-65836

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

No fix yet
Fix from $2,300 2025-12-01
Publiccms HIGH 7.5
CVE-2025-65838

PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

No fix yet
Fix from $1,950 2025-12-01
Publiccms HIGH 8.2
CVE-2025-57516

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via…

No fix yet
Fix from $1,950 2025-09-29
Publiccms CRITICAL 9.8
CVE-2025-25361

An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi…

No fix yet
Fix from $2,300 2025-03-06
Publiccms MEDIUM 5.4
CVE-2024-11070

A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of t…

No fix yet
Fix from $1,600 2024-11-11
Publiccms HIGH 8.8
CVE-2024-31759

An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.

No fix yet
Fix from $1,950 2024-04-16
Publiccms MEDIUM 5.4
CVE-2023-51252

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html …

No fix yet
Fix from $1,600 2024-01-10
Publiccms CRITICAL 9.8
CVE-2023-46990

Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep…

No fix yet
Fix from $2,300 2023-11-20
Publiccms MEDIUM 6.5
CVE-2023-48204

An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/me…

No fix yet
Fix from $1,600 2023-11-16
Publiccms CRITICAL 9.8
CVE-2020-20914

SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.

No fix yet
Fix from $2,300 2023-04-04
Publiccms CRITICAL 9.8
CVE-2020-20915

SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont…

No fix yet
Fix from $2,300 2023-04-04
Publiccms CRITICAL 9.8
CVE-2022-23389EPSS 22%

PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

No fix yet
Fix from $2,300 2022-02-14
Publiccms CRITICAL 9.8
CVE-2021-40881

An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2021-09-15
Publiccms MEDIUM 5.4
CVE-2020-21333

Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.

No fix yet
Fix from $1,600 2021-07-09
Publiccms MEDIUM 5.3
CVE-2018-17368

An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is…

No fix yet
Fix from $1,600 2018-09-23
Publiccms CRITICAL 9.8
CVE-2018-12914

A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct…

No fix yet
Fix from $2,300 2018-06-27
Publiccms MEDIUM 6.5
CVE-2018-12494

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate…

No fix yet
Fix from $1,600 2018-06-15
Publiccms HIGH 8.8
CVE-2018-11500

An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUse…

No fix yet
Fix from $1,950 2018-05-26