Vulnerability index

Browse CVEs

42 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2025-69437 PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the ba… Publiccms after 5.202506.d Fix from $1,9502026-02-27 CRITICAL 9.8 CVE-2026-3289 A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the… Publiccms Mitigation only Fix from $2,3002026-02-27 HIGH 8.1 CVE-2026-1112 A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/public… Publiccms after 5.202506.d Fix from $1,9502026-01-18 HIGH 7.2 CVE-2026-1111 A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/T… Publiccms after 5.202506.d Fix from $1,9502026-01-18 MEDIUM 5.4 CVE-2025-65837 PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module. Publiccms No fix yet Fix from $1,6002025-12-22 HIGH 8.8 CVE-2025-65840 PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController. Publiccms No fix yet Fix from $1,9502025-12-01 CRITICAL 9.1 CVE-2025-65836 PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController. Publiccms No fix yet Fix from $2,3002025-12-01 HIGH 7.5 CVE-2025-65838 PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method. Publiccms No fix yet Fix from $1,9502025-12-01 HIGH 8.2 CVE-2025-57516 OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via… Publiccms No fix yet Fix from $1,9502025-09-29 MEDIUM 6.1 CVE-2025-7953 A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processin… Publiccms 5.202506.b+ Fix from $1,6002025-07-22 MEDIUM 6.1 CVE-2025-7949 A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown fu… Publiccms 5.202506.b+ Fix from $1,6002025-07-22 CRITICAL 9.8 CVE-2025-25361 An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi… Publiccms No fix yet Fix from $2,3002025-03-06 MEDIUM 5.4 CVE-2024-11070 A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of t… Publiccms No fix yet Fix from $1,6002024-11-11 HIGH 7.2 CVE-2024-42523 publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData Publiccms after 4.0.202302.e Fix from $1,9502024-08-23 HIGH 8.8 CVE-2024-40543 PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage. Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40544 PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit. Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40545 An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary c… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40546 An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code … Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40548 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40549 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40550 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40551 An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary … Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 HIGH 8.8 CVE-2024-40552 PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent… Publiccms after 4.0.202302.e Fix from $1,9502024-07-12 MEDIUM 6.5 CVE-2024-40547 PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace. Publiccms after 4.0.202302.e Fix from $1,6002024-07-12 HIGH 8.8 CVE-2024-31759 An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function. Publiccms No fix yet Fix from $1,9502024-04-16 MEDIUM 5.4 CVE-2023-51252 PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html … Publiccms No fix yet Fix from $1,6002024-01-10 CRITICAL 9.8 CVE-2023-46990 Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep… Publiccms No fix yet Fix from $2,3002023-11-20 MEDIUM 6.5 CVE-2023-48204 An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/me… Publiccms No fix yet Fix from $1,6002023-11-16 CRITICAL 9.8 CVE-2023-34852 PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions. Publiccms after 4.0.202302 Fix from $2,3002023-06-15 CRITICAL 9.8 CVE-2020-20914 SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. Publiccms No fix yet Fix from $2,3002023-04-04