CVE-2026-93961
- EPSS 0.42%
- Veröffentlicht 20.09.2026 04:45:09
- Zuletzt bearbeitet 21.09.2026 15:17:36
A security flaw has been discovered in Dromara UJCMS up to 12.3.1. The affected element is the function usernameExist of the file ujcms-cms/src/main/java/com/ujcms/cms/core/web/api/UserController.java of the component UserController. Performing a man...
CVE-2026-78140
- EPSS 0.24%
- Veröffentlicht 23.08.2026 20:16:50
- Zuletzt bearbeitet 24.08.2026 20:17:22
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipu...
CVE-2026-2954
- EPSS 0.33%
- Veröffentlicht 22.02.2026 15:02:17
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url resu...
CVE-2026-2953
- EPSS 0.76%
- Veröffentlicht 22.02.2026 14:16:02
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulation leads to path traversal. The attack may be perfor...
CVE-2025-2491
- EPSS 0.33%
- Veröffentlicht 18.03.2025 14:31:03
- Zuletzt bearbeitet 04.11.2025 19:41:43
A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The man...
CVE-2025-2490
- EPSS 0.32%
- Veröffentlicht 18.03.2025 14:00:07
- Zuletzt bearbeitet 06.11.2025 19:39:49
A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upl...
CVE-2024-55451
- EPSS 0.31%
- Veröffentlicht 16.12.2024 23:15:06
- Zuletzt bearbeitet 24.04.2025 15:26:43
A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3. The vulnerability arises from insufficient sanitization of embedded attributes in uploaded SVG files. When a malicious...
CVE-2024-55452
- EPSS 0.26%
- Veröffentlicht 16.12.2024 23:15:06
- Zuletzt bearbeitet 24.04.2025 15:20:21
A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. This vulnerability allows authenticated attackers to redirect unprivileged users to an arbitrary, atta...
CVE-2024-12483
- EPSS 3.51%
- Veröffentlicht 12.12.2024 01:40:29
- Zuletzt bearbeitet 13.12.2024 17:12:32
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the...
CVE-2023-51806
- EPSS 0.55%
- Veröffentlicht 12.01.2024 13:15:11
- Zuletzt bearbeitet 21.11.2024 08:38:51
File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.