Vulnerabilities > Publiccms

DATE CVE VULNERABILITY TITLE RISK
2022-02-14 CVE-2022-23389 OS Command Injection vulnerability in Publiccms 4.0
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
network
low complexity
publiccms CWE-78
critical
9.8
2021-09-15 CVE-2021-40881 Unspecified vulnerability in Publiccms 4.0
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
network
low complexity
publiccms
critical
9.8
2021-07-09 CVE-2020-21333 Cross-site Scripting vulnerability in Publiccms 4.0
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
network
low complexity
publiccms CWE-79
5.4
2018-11-04 CVE-2018-18927 Cross-site Scripting vulnerability in Publiccms 4.0
An issue was discovered in PublicCMS V4.0.
network
low complexity
publiccms CWE-79
4.8
2018-09-23 CVE-2018-17368 Unspecified vulnerability in Publiccms 4.0.180825
An issue was discovered in PublicCMS V4.0.180825.
network
low complexity
publiccms
5.3
2018-06-27 CVE-2018-12914 Unrestricted Upload of File with Dangerous Type vulnerability in Publiccms 4.0.20180210
A remote code execution issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-434
critical
9.8
2018-06-15 CVE-2018-12494 Path Traversal vulnerability in Publiccms 4.0.20180210
An issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-22
6.5
2018-06-15 CVE-2018-12493 Path Traversal vulnerability in Publiccms 4.0.20180210
An issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-22
6.5
2018-05-26 CVE-2018-11500 Cross-Site Request Forgery (CSRF) vulnerability in Publiccms 4.0.20180210
An issue was discovered in PublicCMS V4.0.20180210.
network
low complexity
publiccms CWE-352
8.8