Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Publiccms CRITICAL 9.8
CVE-2020-20915

SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont…

No fix yet
Fix from $2,300 2023-04-04
Publiccms MEDIUM 6.1
CVE-2022-3950

A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the…

Fix: 4.0.202204.d+
Fix from $1,600 2022-11-11
Publiccms CRITICAL 9.8
CVE-2021-27693

Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

Fix: 4.0.202011.b+
Fix from $2,300 2022-09-02
Publiccms MEDIUM 5.3
CVE-2022-29784

PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.

Fix: after 4.0.202204.a
Fix from $1,600 2022-06-03
Publiccms CRITICAL 9.8
CVE-2022-23389EPSS 22%

PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

No fix yet
Fix from $2,300 2022-02-14
Publiccms CRITICAL 9.8
CVE-2021-40881

An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.

No fix yet
Fix from $2,300 2021-09-15
Publiccms MEDIUM 5.4
CVE-2020-21333

Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.

No fix yet
Fix from $1,600 2021-07-09
Publiccms MEDIUM 5.3
CVE-2018-17368

An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is…

No fix yet
Fix from $1,600 2018-09-23
Publiccms CRITICAL 9.8
CVE-2018-12914

A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct…

No fix yet
Fix from $2,300 2018-06-27
Publiccms MEDIUM 6.5
CVE-2018-12493

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/…

Patch available
Fix from $1,600 2018-06-15
Publiccms MEDIUM 6.5
CVE-2018-12494

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate…

No fix yet
Fix from $1,600 2018-06-15
Publiccms HIGH 8.8
CVE-2018-11500

An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUse…

No fix yet
Fix from $1,950 2018-05-26