CVE-2025-7953
- EPSS 0.04%
- Veröffentlicht 22.07.2025 03:32:05
- Zuletzt bearbeitet 20.08.2025 20:19:27
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects some unknown processing of the file publiccms-parent/publiccms/src/main/webapp/resource/plugins/pdfjs/viewer.html. The mani...
CVE-2025-7949
- EPSS 0.04%
- Veröffentlicht 22.07.2025 01:32:06
- Zuletzt bearbeitet 20.08.2025 20:20:09
A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file publiccms-parent/publiccms/src/main/resources/templates/admin/cmsDiy/preview....
CVE-2025-25361
- EPSS 0.81%
- Veröffentlicht 06.03.2025 19:15:27
- Zuletzt bearbeitet 01.07.2025 21:23:28
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbitrary code via uploading a crafted svg or xml file.
CVE-2024-11175
- EPSS 0.1%
- Veröffentlicht 13.11.2024 16:15:17
- Zuletzt bearbeitet 15.11.2024 22:50:48
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component Voting Management. The manipulation leads to cross site scripting. The attac...
CVE-2024-11070
- EPSS 0.13%
- Veröffentlicht 11.11.2024 15:15:04
- Zuletzt bearbeitet 23.11.2024 01:31:09
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unknown processing of the file /admin/cmsTagType/save of the component Tag Type Handler. The manipulation of the argument na...
CVE-2024-46410
- EPSS 0.27%
- Veröffentlicht 08.10.2024 18:15:30
- Zuletzt bearbeitet 23.04.2025 01:14:15
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category Managment feature
CVE-2024-42523
- EPSS 0.12%
- Veröffentlicht 23.08.2024 16:15:06
- Zuletzt bearbeitet 21.04.2025 14:42:42
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
CVE-2024-40546
- EPSS 0.32%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:31:17
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.
CVE-2024-40552
- EPSS 0.46%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 26.03.2025 20:15:20
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.
CVE-2024-40551
- EPSS 0.23%
- Veröffentlicht 12.07.2024 16:15:05
- Zuletzt bearbeitet 21.11.2024 09:31:18
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.