Vulnerabilities (CVE)

Filtered by vendor Publiccms Subscribe
Total 47 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-40547 1 Publiccms 1 Publiccms 2026-06-17 N/A 6.5 MEDIUM
PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.
CVE-2024-40546 1 Publiccms 1 Publiccms 2026-06-17 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40545 1 Publiccms 1 Publiccms 2026-06-17 N/A 8.8 HIGH
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40544 1 Publiccms 1 Publiccms 2026-06-17 N/A 8.8 HIGH
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.
CVE-2024-40543 1 Publiccms 1 Publiccms 2026-06-17 N/A 8.8 HIGH
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
CVE-2024-31759 1 Publiccms 1 Publiccms 2026-06-17 N/A 8.8 HIGH
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
CVE-2024-2911 1 Publiccms 1 Publiccms 2026-06-17 5.0 MEDIUM 4.3 MEDIUM
A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-11175 1 Publiccms 1 Publiccms 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component Voting Management. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named b9530b9cc1f5cfdad4b637874f59029a6283a65c. It is recommended to apply a patch to fix this issue.
CVE-2024-11070 1 Publiccms 1 Publiccms 2026-06-17 4.0 MEDIUM 3.5 LOW
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of the component Tag Type Handler. The manipulation of the argument name leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVE-2023-51252 1 Publiccms 1 Publiccms 2026-06-17 N/A 5.4 MEDIUM
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.
CVE-2023-48204 1 Publiccms 1 Publiccms 2026-06-17 N/A 6.5 MEDIUM
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.
CVE-2023-46990 1 Publiccms 1 Publiccms 2026-06-17 N/A 9.8 CRITICAL
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.
CVE-2023-34852 1 Publiccms 1 Publiccms 2026-06-17 N/A 9.8 CRITICAL
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
CVE-2022-3950 1 Publiccms 1 Publiccms 2026-06-17 N/A 3.5 LOW
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a972dc9b1c94aea2d84478bf26283904c21e4ca2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213456.
CVE-2022-29784 1 Publiccms 1 Publiccms 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
CVE-2022-23389 1 Publiccms 1 Publiccms 2026-06-17 7.5 HIGH 9.8 CRITICAL
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
CVE-2021-40881 1 Publiccms 1 Publiccms 2026-06-17 7.5 HIGH 9.8 CRITICAL
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
CVE-2021-27693 1 Publiccms 1 Publiccms 2026-06-17 N/A 9.8 CRITICAL
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.
CVE-2020-21333 1 Publiccms 1 Publiccms 2026-06-17 3.5 LOW 5.4 MEDIUM
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
CVE-2020-20915 1 Publiccms 1 Publiccms 2026-06-17 N/A 9.8 CRITICAL
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.