Home/Product/publiccms
Product

publiccms

47 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-69437
<= 5.202506.d
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF securi
8.7HIGH
CVE-2026-3289
all versions
A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheCo
6.3MEDIUM
CVE-2026-2010
<= 4.0.202506.d
A vulnerability has been found in Sanluan PublicCMS up to 4.0.202506.d/5.202506.d/6.202506.d. Impacted is the function Paid of the
4.2MEDIUM
CVE-2026-1112
<= 5.202506.d
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/m
5.4MEDIUM
CVE-2026-1111
<= 5.202506.d
A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/con
4.7MEDIUM
CVE-2025-65837
all versions
PublicCMS V5.202506.b is vulnerable to Cross Site Scripting (XSS) in the Content Search module.
5.4MEDIUM
CVE-2025-65840
all versions
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
8.8HIGH
CVE-2025-65838
all versions
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
7.5HIGH
CVE-2025-65836
all versions
PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
9.1CRITICAL
CVE-2025-57516
all versions
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arb
8.2HIGH
CVE-2025-7953
< 5.202506.b
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS up to 5.202506.a. This issue affects som
3.5LOW
CVE-2025-7949
< 5.202506.b
A vulnerability was found in Sanluan PublicCMS up to 5.202506.a. It has been declared as problematic. Affected by this vulnerabili
3.5LOW
CVE-2025-25361
all versions
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attack
9.8CRITICAL
CVE-2024-11175
all versions
A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of th
3.5LOW
CVE-2024-11070
all versions
A vulnerability, which was classified as problematic, has been found in Sanluan PublicCMS 5.202406.d. This issue affects some unkn
3.5LOW
CVE-2024-46410
all versions
PublicCMS V4.0.202406.d was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted script to the Category
4.8MEDIUM
CVE-2024-42523
<= 4.0.202302.e
publiccms V4.0.202302.e and before is vulnerable to Any File Upload via publiccms/admin/cmsTemplate/saveMetaData
7.2HIGH
CVE-2024-40552
<= 4.0.202302.e
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /s
8.8HIGH
CVE-2024-40551
<= 4.0.202302.e
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to
8.8HIGH
CVE-2024-40550
<= 4.0.202302.e
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows a
8.8HIGH
CVE-2024-40549
<= 4.0.202302.e
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers t
8.8HIGH
CVE-2024-40548
<= 4.0.202302.e
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to exe
8.8HIGH
CVE-2024-40547
<= 4.0.202302.e
PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cms
6.5MEDIUM
CVE-2024-40546
<= 4.0.202302.e
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to exec
8.8HIGH
CVE-2024-40545
<= 4.0.202302.e
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to
8.8HIGH
CVE-2024-40544
<= 4.0.202302.e
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTa
8.8HIGH
CVE-2024-40543
<= 4.0.202302.e
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=cat
8.8HIGH
CVE-2024-31759
all versions
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
8.8HIGH
CVE-2024-2911
all versions
A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. Th
4.3MEDIUM
CVE-2023-51252
all versions
PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided,
5.4MEDIUM
CVE-2023-46990
all versions
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted scr
9.8CRITICAL
CVE-2023-48204
all versions
An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters para
6.5MEDIUM
CVE-2023-34852
<= 4.0.202302
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
9.8CRITICAL
CVE-2020-20915
all versions
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the t
9.8CRITICAL
CVE-2020-20914
all versions
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql param
9.8CRITICAL
CVE-2022-3950
< 4.0.202204.d
A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the fil
3.5LOW
CVE-2021-27693
< 4.0.202011.b
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is
9.8CRITICAL
CVE-2022-29784
<= 4.0.202204.a
PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.
5.3MEDIUM
CVE-2022-23389
all versions
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
9.8CRITICAL
CVE-2021-40881
all versions
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
9.8CRITICAL
CVE-2020-21333
all versions
Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.
5.4MEDIUM
CVE-2018-18927
all versions
An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'cla
4.8MEDIUM
CVE-2018-17368
all versions
An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whet
5.3MEDIUM
CVE-2018-12914
all versions
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp
9.8CRITICAL
CVE-2018-12494
all versions
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via a
6.5MEDIUM
CVE-2018-12493
all versions
An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via a
6.5MEDIUM
CVE-2018-11500
all versions
An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurr
8.8HIGH
threatengine.sh