VendorsUCMS Projectucmsall versions
Vulnerabilities

UCMS Project Ucms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

28CVEs
CVE-2020-25537
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
Published 2020-11-30 · Modified
10.0EPSS 0.019
CVE-2020-25483
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
Published 2020-10-23 · Modified
9.8EPSS 0.087
CVE-2018-17036
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
Published 2018-09-14 · Modified
9.8EPSS 0.017
CVE-2022-38297
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
Published 2022-09-12 · Modified
9.8EPSS 0.012
CVE-2018-17035
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
Published 2018-09-14 · Modified
9.8EPSS 0.011
CVE-2022-35426
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
Published 2022-08-09 · Modified
9.8EPSS 0.011
CVE-2023-1303
UCMS System File Management Module fileedit.php unrestricted upload
Published 2023-03-09 · Modified
9.8EPSS 0.008
CVE-2022-28443
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
Published 2022-04-21 · Modified
9.1EPSS 0.010
CVE-2022-28440
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-04-21 · Modified
8.8EPSS 0.017
CVE-2018-20599
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
Published 2018-12-30 · Modified
8.8EPSS 0.015
CVE-2019-12251
sadmin/ceditpost.php in UCMS 1.4.7 allows SQL Injection via the index.php?do=sadmin_ceditpost cvalue parameter.
Published 2019-05-21 · Modified
8.8EPSS 0.012
CVE-2018-19437
UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.
Published 2018-11-22 · Modified
8.8EPSS 0.011
CVE-2018-17037
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
Published 2018-09-14 · Modified
8.8EPSS 0.010
CVE-2022-42234
There is a file inclusion vulnerability in the template management module in UCMS 1.6
Published 2022-10-14 · Modified
8.8EPSS 0.009
CVE-2018-20598
UCMS 1.4.7 has ?do=user_addpost CSRF.
Published 2018-12-30 · Modified
8.8EPSS 0.005
CVE-2022-28444
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
Published 2022-04-21 · Modified
7.5EPSS 0.015
CVE-2018-16804
An issue was discovered in UCMS 1.4.6. There is XSS in the title bar, as demonstrated by a do=list request.
Published 2019-03-07 · Modified
6.1EPSS 0.008
CVE-2018-20600
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
Published 2018-12-30 · Modified
6.1EPSS 0.007
CVE-2018-17034
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
Published 2018-09-14 · Modified
6.1EPSS 0.007
CVE-2018-17320
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.
Published 2018-09-21 · Modified
6.1EPSS 0.007
CVE-2022-38527
UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.
Published 2022-09-19 · Modified
6.1EPSS 0.006
CVE-2023-2294
UCMS Column Configuration saddpost.php cross site scripting
Published 2023-04-26 · Modified
6.1EPSS 0.005
CVE-2023-5015
UCMS cross site scripting
Published 2023-09-17 · Modified
6.1EPSS 0.005
CVE-2020-20781
A stored cross-site scripting (XSS) vulnerability in /ucms/index.php?do=list_edit of UCMS 1.4.7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the title, key words, description or content text fields.
Published 2021-09-29 · Modified
5.4EPSS 0.005
CVE-2020-24981
An Incorrect Access Control vulnerability exists in /ucms/chk.php in UCMS 1.4.8. This results in information leak via an error message caused by directly accessing the website built by UCMS.
Published 2020-09-04 · Modified
5.3EPSS 0.010
CVE-2021-25809
UCMS 1.5.0 was discovered to contain a physical path leakage via an error message returned by the adminchannelscache() function in top.php.
Published 2021-07-23 · Modified
5.3EPSS 0.009
CVE-2018-20601
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
Published 2018-12-30 · Modified
4.8EPSS 0.006
CVE-2018-20597
UCMS 1.4.7 has XSS via the dir parameter in an index.php sadmin_fileedit action.
Published 2018-12-30 · Modified
4.8EPSS 0.006