Vulnerability index

Browse CVEs

26 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ucms MEDIUM 6.1
CVE-2023-5015

A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file ajax.php?do=strarraylist.…

No fix yet
Fix from $1,600 2023-09-17
Ucms MEDIUM 6.1
CVE-2023-2294

A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file saddpost.php of the componen…

No fix yet
Fix from $1,600 2023-04-26
Ucms CRITICAL 9.8
CVE-2023-1303

A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadmin/fileedit.php of the c…

Mitigation only
Fix from $2,300 2023-03-09
Ucms HIGH 8.8
CVE-2022-42234

There is a file inclusion vulnerability in the template management module in UCMS 1.6

No fix yet
Fix from $1,950 2022-10-14
Ucms MEDIUM 6.1
CVE-2022-38527

UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.

No fix yet
Fix from $1,600 2022-09-19
Ucms CRITICAL 9.8
CVE-2022-38297

UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.

No fix yet
Fix from $2,300 2022-09-12
Ucms CRITICAL 9.8
CVE-2022-35426

UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.

No fix yet
Fix from $2,300 2022-08-10
Ucms CRITICAL 9.1
CVE-2022-28443

UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.

No fix yet
Fix from $2,300 2022-04-21
Ucms HIGH 8.8
CVE-2022-28440

An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.

No fix yet
Fix from $1,950 2022-04-21
Ucms HIGH 7.5
CVE-2022-28444

UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.

No fix yet
Fix from $1,950 2022-04-21
Ucms MEDIUM 5.4
CVE-2020-20781

A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or …

No fix yet
Fix from $1,600 2021-09-29
Ucms MEDIUM 5.3
CVE-2021-25809

UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.

No fix yet
Fix from $1,600 2021-07-23
Ucms CRITICAL 9.8
CVE-2020-25537

File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.

No fix yet
Fix from $2,300 2020-11-30
Ucms CRITICAL 9.8
CVE-2020-25483EPSS 9%

An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the s…

No fix yet
Fix from $2,300 2020-10-23
Ucms MEDIUM 5.3
CVE-2020-24981

An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by dire…

No fix yet
Fix from $1,600 2020-09-04
Ucms HIGH 8.8
CVE-2019-12251

sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.

No fix yet
Fix from $1,950 2019-05-21
Ucms MEDIUM 6.1
CVE-2018-16804

An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.

No fix yet
Fix from $1,600 2019-03-07
Ucms HIGH 8.8
CVE-2018-20598

UCMS 1.4.7 has ?do=user_addpost CSRF.

No fix yet
Fix from $1,950 2018-12-30
Ucms HIGH 8.8
CVE-2018-20599

UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.

No fix yet
Fix from $1,950 2018-12-30
Ucms MEDIUM 6.1
CVE-2018-20600

sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.

No fix yet
Fix from $1,600 2018-12-30
Ucms HIGH 8.8
CVE-2018-19437

UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie …

No fix yet
Fix from $1,950 2018-11-22
Ucms MEDIUM 6.1
CVE-2018-17320

An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.

Mitigation only
Fix from $1,600 2018-09-21
Ucms CRITICAL 9.8
CVE-2018-17035

UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.

No fix yet
Fix from $2,300 2018-09-14
Ucms CRITICAL 9.8
CVE-2018-17036

An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, …

No fix yet
Fix from $2,300 2018-09-14
Ucms HIGH 8.8
CVE-2018-17037

user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.

No fix yet
Fix from $1,950 2018-09-14
Ucms MEDIUM 6.1
CVE-2018-17034

UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.

No fix yet
Fix from $1,600 2018-09-14