CVE-2025-69437
- EPSS 0.04%
- Veröffentlicht 27.02.2026 17:16:26
- Zuletzt bearbeitet 05.03.2026 02:09:43
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system an...
CVE-2026-3289
- EPSS 0.09%
- Veröffentlicht 27.02.2026 04:32:10
- Zuletzt bearbeitet 02.03.2026 15:19:35
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack...
CVE-2026-2010
- EPSS 0.07%
- Veröffentlicht 06.02.2026 08:15:54
- Zuletzt bearbeitet 17.02.2026 19:12:22
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the c...
CVE-2026-1112
- EPSS 0.02%
- Veröffentlicht 18.01.2026 06:02:06
- Zuletzt bearbeitet 05.02.2026 19:45:32
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deletion Endpoint...
CVE-2026-1111
- EPSS 0.16%
- Veröffentlicht 18.01.2026 05:32:05
- Zuletzt bearbeitet 05.02.2026 19:48:24
A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/TaskTemplateAdminController.java of the component Task Template Management Handler. Such manipulation ...
CVE-2025-65837
- EPSS 0.04%
- Veröffentlicht 22.12.2025 00:00:00
- Zuletzt bearbeitet 05.01.2026 16:24:35
PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
CVE-2025-65840
- EPSS 0.03%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:58:21
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
CVE-2025-65838
- EPSS 0.07%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:09:42
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
CVE-2025-65836
- EPSS 0.05%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:09:55
PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
CVE-2025-57516
- EPSS 2.24%
- Veröffentlicht 29.09.2025 15:16:08
- Zuletzt bearbeitet 23.12.2025 18:49:30
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.