VendorsUCMS Projectucms1.6
Vulnerabilities

UCMS Project Ucms 1.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2018-17036
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
Published 2018-09-14 · Modified
9.8EPSS 0.017
CVE-2022-38297
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
Published 2022-09-12 · Modified
9.8EPSS 0.012
CVE-2022-35426
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
Published 2022-08-09 · Modified
9.8EPSS 0.011
CVE-2023-1303
UCMS System File Management Module fileedit.php unrestricted upload
Published 2023-03-09 · Modified
9.8EPSS 0.008
CVE-2022-28443
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
Published 2022-04-21 · Modified
9.1EPSS 0.010
CVE-2022-28440
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
Published 2022-04-21 · Modified
8.8EPSS 0.017
CVE-2022-42234
There is a file inclusion vulnerability in the template management module in UCMS 1.6
Published 2022-10-14 · Modified
8.8EPSS 0.009
CVE-2022-28444
UCMS v1.6 was discovered to contain an arbitrary file read vulnerability.
Published 2022-04-21 · Modified
7.5EPSS 0.015
CVE-2022-38527
UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Management page.
Published 2022-09-19 · Modified
6.1EPSS 0.006
CVE-2023-2294
UCMS Column Configuration saddpost.php cross site scripting
Published 2023-04-26 · Modified
6.1EPSS 0.005