Publiccms

Publiccms

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.04%
  • Veröffentlicht 27.02.2026 17:16:26
  • Zuletzt bearbeitet 05.03.2026 02:09:43

PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a user uploads a PDF file containing a malicious payload to the system an...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 27.02.2026 04:32:10
  • Zuletzt bearbeitet 02.03.2026 15:19:35

A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack...

Exploit
  • EPSS 0.07%
  • Veröffentlicht 06.02.2026 08:15:54
  • Zuletzt bearbeitet 17.02.2026 19:12:22

A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the file publiccms-parent/publiccms-trade/src/main/java/com/publiccms/logic/service/trade/TradePaymentService.java of the c...

Exploit
  • EPSS 0.02%
  • Veröffentlicht 18.01.2026 06:02:06
  • Zuletzt bearbeitet 05.02.2026 19:45:32

A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deletion Endpoint...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 18.01.2026 05:32:05
  • Zuletzt bearbeitet 05.02.2026 19:48:24

A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/TaskTemplateAdminController.java of the component Task Template Management Handler. Such manipulation ...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 22.12.2025 00:00:00
  • Zuletzt bearbeitet 05.01.2026 16:24:35

PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 01.12.2025 00:00:00
  • Zuletzt bearbeitet 04.12.2025 18:58:21

PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 01.12.2025 00:00:00
  • Zuletzt bearbeitet 04.12.2025 18:09:42

PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.

Exploit
  • EPSS 0.05%
  • Veröffentlicht 01.12.2025 00:00:00
  • Zuletzt bearbeitet 04.12.2025 18:09:55

PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.

Exploit
  • EPSS 2.24%
  • Veröffentlicht 29.09.2025 15:16:08
  • Zuletzt bearbeitet 23.12.2025 18:49:30

OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary commands via crafted DATABASE, USERNAME, or PASSWORD variables to the backupDB.bat file.