CVE-2026-36521
- EPSS 0.18%
- Veröffentlicht 15.06.2026 00:00:00
- Zuletzt bearbeitet 16.06.2026 19:16:35
PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
CVE-2025-69437
- EPSS 0.35%
- Veröffentlicht 27.02.2026 17:16:26
- Zuletzt bearbeitet 05.03.2026 02:09:43
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system an...
CVE-2026-3289
- EPSS 0.68%
- Veröffentlicht 27.02.2026 04:32:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack...
CVE-2026-2010
- EPSS 0.33%
- Veröffentlicht 06.02.2026 08:15:54
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the c...
CVE-2026-1112
- EPSS 0.39%
- Veröffentlicht 18.01.2026 06:02:06
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deletion Endpoint...
CVE-2026-1111
- EPSS 0.64%
- Veröffentlicht 18.01.2026 05:32:05
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/TaskTemplateAdminController.java of the component Task Template Management Handler. Such manipulation ...
CVE-2025-65837
- EPSS 0.14%
- Veröffentlicht 22.12.2025 00:00:00
- Zuletzt bearbeitet 05.01.2026 16:24:35
PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
CVE-2025-65840
- EPSS 0.14%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:58:21
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
CVE-2025-65838
- EPSS 0.38%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:09:42
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
CVE-2025-65836
- EPSS 0.28%
- Veröffentlicht 01.12.2025 00:00:00
- Zuletzt bearbeitet 04.12.2025 18:09:55
PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.