Ulicms

Ulicms

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.12.2025 22:44:55
  • Zuletzt bearbeitet 18.12.2025 19:38:26

UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG files through the file management interface that execute arbitrary scrip...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 17.12.2025 22:44:54
  • Zuletzt bearbeitet 18.12.2025 19:16:19

UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers can send a crafted POST request to /dist/admin/index.php with specific ...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 17.12.2025 22:44:54
  • Zuletzt bearbeitet 18.12.2025 19:38:40

UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar upload. Attackers can trigger code execution by visiting the uploaded file...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 17.12.2025 22:44:49
  • Zuletzt bearbeitet 18.12.2025 15:15:50

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with sp...

  • EPSS 0.36%
  • Veröffentlicht 07.05.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:06

UliCMS before 2020.2 has XSS during PackageController uninstall.

  • EPSS 0.4%
  • Veröffentlicht 07.05.2020 20:15:12
  • Zuletzt bearbeitet 21.11.2024 05:00:06

UliCMS before 2020.2 has PageController stored XSS.

Exploit
  • EPSS 3.91%
  • Veröffentlicht 08.05.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 04:21:01

Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.php, the go parameter to /admin/index.php?register=register, or the erro...