Vulnerabilities > Publiccms
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-07-12 | CVE-2024-40551 | Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file. | 8.8 |
2024-07-12 | CVE-2024-40552 | Unspecified vulnerability in Publiccms PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java. | 8.8 |
2024-01-10 | CVE-2023-51252 | Cross-site Scripting vulnerability in Publiccms 4.0 PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). | 5.4 |
2023-11-20 | CVE-2023-46990 | Deserialization of Untrusted Data vulnerability in Publiccms 4.0.202302.E Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function. | 9.8 |
2023-11-16 | CVE-2023-48204 | Server-Side Request Forgery (SSRF) vulnerability in Publiccms 4.0.202302.E An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component. | 6.5 |
2023-06-15 | CVE-2023-34852 | Unspecified vulnerability in Publiccms PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions. | 9.8 |
2023-04-04 | CVE-2020-20914 | SQL Injection vulnerability in Publiccms 4.0 SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. | 9.8 |
2023-04-04 | CVE-2020-20915 | SQL Injection vulnerability in Publiccms 4.0 SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl. | 9.8 |
2022-11-11 | CVE-2022-3950 | Cross-site Scripting vulnerability in Publiccms A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. | 6.1 |
2022-09-02 | CVE-2021-27693 | Server-Side Request Forgery (SSRF) vulnerability in Publiccms Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage. | 9.8 |