CVE-2023-53925
- EPSS 0.03%
- Veröffentlicht 17.12.2025 22:44:55
- Zuletzt bearbeitet 18.12.2025 19:38:26
UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scrip...
CVE-2023-53923
- EPSS 0.08%
- Veröffentlicht 17.12.2025 22:44:54
- Zuletzt bearbeitet 18.12.2025 19:16:19
UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific ...
CVE-2023-53924
- EPSS 0.24%
- Veröffentlicht 17.12.2025 22:44:54
- Zuletzt bearbeitet 18.12.2025 19:38:40
UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file...
CVE-2023-53914
- EPSS 0.2%
- Veröffentlicht 17.12.2025 22:44:49
- Zuletzt bearbeitet 18.12.2025 15:15:50
UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with sp...
CVE-2020-12703
- EPSS 0.36%
- Veröffentlicht 07.05.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:06
UliCMS before 2020.2 has XSS during PackageController uninstall.
CVE-2020-12704
- EPSS 0.4%
- Veröffentlicht 07.05.2020 20:15:12
- Zuletzt bearbeitet 21.11.2024 05:00:06
UliCMS before 2020.2 has PageController stored XSS.
CVE-2019-11398
- EPSS 3.91%
- Veröffentlicht 08.05.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 04:21:01
Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the erro...