Vulnerability index

Browse CVEs

21 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-3289 A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the… Publiccms Mitigation only Fix from $2,3002026-02-27 MEDIUM 5.4 CVE-2025-65837 PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module. Publiccms No fix yet Fix from $1,6002025-12-22 HIGH 8.8 CVE-2025-65840 PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. Publiccms No fix yet Fix from $1,9502025-12-01 CRITICAL 9.1 CVE-2025-65836 PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. Publiccms No fix yet Fix from $2,3002025-12-01 HIGH 7.5 CVE-2025-65838 PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method. Publiccms No fix yet Fix from $1,9502025-12-01 HIGH 8.2 CVE-2025-57516 OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via… Publiccms No fix yet Fix from $1,9502025-09-29 CRITICAL 9.8 CVE-2025-25361 An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi… Publiccms No fix yet Fix from $2,3002025-03-06 MEDIUM 5.4 CVE-2024-11070 A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of t… Publiccms No fix yet Fix from $1,6002024-11-11 HIGH 8.8 CVE-2024-31759 An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function. Publiccms No fix yet Fix from $1,9502024-04-16 MEDIUM 5.4 CVE-2023-51252 PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html … Publiccms No fix yet Fix from $1,6002024-01-10 CRITICAL 9.8 CVE-2023-46990 Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep… Publiccms No fix yet Fix from $2,3002023-11-20 MEDIUM 6.5 CVE-2023-48204 An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/me… Publiccms No fix yet Fix from $1,6002023-11-16 CRITICAL 9.8 CVE-2020-20914 SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. Publiccms No fix yet Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2020-20915 SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont… Publiccms No fix yet Fix from $2,3002023-04-04 CRITICAL 9.8 CVE-2022-23389EPSS 22% PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. Publiccms No fix yet Fix from $2,3002022-02-14 CRITICAL 9.8 CVE-2021-40881 An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code. Publiccms No fix yet Fix from $2,3002021-09-15 MEDIUM 5.4 CVE-2020-21333 Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case. Publiccms No fix yet Fix from $1,6002021-07-09 MEDIUM 5.3 CVE-2018-17368 An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is… Publiccms No fix yet Fix from $1,6002018-09-23 CRITICAL 9.8 CVE-2018-12914 A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct… Publiccms No fix yet Fix from $2,3002018-06-27 MEDIUM 6.5 CVE-2018-12494 An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate… Publiccms No fix yet Fix from $1,6002018-06-15 HIGH 8.8 CVE-2018-11500 An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUse… Publiccms No fix yet Fix from $1,9502018-05-26