Vulnerability index

Browse CVEs

14 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Ujcms CRITICAL 9.8
CVE-2026-2954

A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of t…

Mitigation only
Fix from $2,300 2026-02-22
Ujcms CRITICAL 9.1
CVE-2026-2953

A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete o…

No fix yet
Fix from $2,300 2026-02-22
Ujcms MEDIUM 5.4
CVE-2025-2491

A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cm…

No fix yet
Fix from $1,600 2025-03-18
Ujcms MEDIUM 5.4
CVE-2025-2490

A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the fi…

No fix yet
Fix from $1,600 2025-03-18
Ujcms MEDIUM 5.4
CVE-2024-55452

A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. T…

No fix yet
Fix from $1,600 2024-12-16
Jspxcms MEDIUM 6.1
CVE-2024-1257

A vulnerability was found in Jspxcms 10.2.0. It has been classified as problematic. Affected is an unknown function of the file /ext/collect/find_tex…

No fix yet
Fix from $1,600 2024-02-06
Jspxcms MEDIUM 5.4
CVE-2024-0599

A vulnerability was found in Jspxcms 10.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the f…

No fix yet
Fix from $1,600 2024-01-16
Ujcms MEDIUM 5.4
CVE-2023-51806

File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.

No fix yet
Fix from $1,600 2024-01-12
Ujcms CRITICAL 9.8
CVE-2023-51350

A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-…

No fix yet
Fix from $2,300 2024-01-11
Ujcms CRITICAL 9.8
CVE-2023-34747EPSS 20%

File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.

No fix yet
Fix from $2,300 2023-06-14
Ujcms CRITICAL 9.8
CVE-2023-34865

Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.

No fix yet
Fix from $2,300 2023-06-14
Ujcms HIGH 7.5
CVE-2023-34878

An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/downl…

No fix yet
Fix from $1,950 2023-06-14
Jspxcms MEDIUM 6.5
CVE-2022-28090

Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.

No fix yet
Fix from $1,600 2022-05-04
Jspxcms CRITICAL 9.8
CVE-2022-23329EPSS 14%

A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via uploadin…

No fix yet
Fix from $2,300 2022-02-04