Vulnerabilities > Publiccms

DATE CVE VULNERABILITY TITLE RISK
2024-07-12 CVE-2024-40551 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
network
low complexity
publiccms CWE-434
8.8
2024-07-12 CVE-2024-40552 Unspecified vulnerability in Publiccms
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
network
low complexity
publiccms
8.8
2024-01-10 CVE-2023-51252 Cross-site Scripting vulnerability in Publiccms 4.0
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS).
network
low complexity
publiccms CWE-79
5.4
2023-11-20 CVE-2023-46990 Deserialization of Untrusted Data vulnerability in Publiccms 4.0.202302.E
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
network
low complexity
publiccms CWE-502
critical
9.8
2023-11-16 CVE-2023-48204 Server-Side Request Forgery (SSRF) vulnerability in Publiccms 4.0.202302.E
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
network
low complexity
publiccms CWE-918
6.5
2023-06-15 CVE-2023-34852 Unspecified vulnerability in Publiccms
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
network
low complexity
publiccms
critical
9.8
2023-04-04 CVE-2020-20914 SQL Injection vulnerability in Publiccms 4.0
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
network
low complexity
publiccms CWE-89
critical
9.8
2023-04-04 CVE-2020-20915 SQL Injection vulnerability in Publiccms 4.0
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.
network
low complexity
publiccms CWE-89
critical
9.8
2022-11-11 CVE-2022-3950 Cross-site Scripting vulnerability in Publiccms
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS.
network
low complexity
publiccms CWE-79
6.1
2022-09-02 CVE-2021-27693 Server-Side Request Forgery (SSRF) vulnerability in Publiccms
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
network
low complexity
publiccms CWE-918
critical
9.8