Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-2954 A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of t… Ujcms Mitigation only Fix from $2,3002026-02-22 CRITICAL 9.1 CVE-2026-2953 A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o… Ujcms No fix yet Fix from $2,3002026-02-22 MEDIUM 5.4 CVE-2025-2491 A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cm… Ujcms No fix yet Fix from $1,6002025-03-18 MEDIUM 5.4 CVE-2025-2490 A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the fi… Ujcms No fix yet Fix from $1,6002025-03-18 MEDIUM 5.4 CVE-2024-55452 A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. T… Ujcms No fix yet Fix from $1,6002024-12-16 MEDIUM 6.1 CVE-2024-1257 A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_tex… Jspxcms No fix yet Fix from $1,6002024-02-06 MEDIUM 5.4 CVE-2024-0599 A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the f… Jspxcms No fix yet Fix from $1,6002024-01-16 MEDIUM 5.4 CVE-2023-51806 File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file. Ujcms No fix yet Fix from $1,6002024-01-12 CRITICAL 9.8 CVE-2023-51350 A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-… Ujcms No fix yet Fix from $2,3002024-01-11 CRITICAL 9.8 CVE-2023-34747EPSS 20% File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload. Ujcms No fix yet Fix from $2,3002023-06-14 CRITICAL 9.8 CVE-2023-34865 Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature. Ujcms No fix yet Fix from $2,3002023-06-14 HIGH 7.5 CVE-2023-34878 An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/downl… Ujcms No fix yet Fix from $1,9502023-06-14 MEDIUM 6.5 CVE-2022-28090 Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=. Jspxcms No fix yet Fix from $1,6002022-05-04 CRITICAL 9.8 CVE-2022-23329EPSS 14% A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploadin… Jspxcms No fix yet Fix from $2,3002022-02-04