VendorsUtcms Projectutcms9.0
Vulnerabilities

Utcms Project Utcms 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2025-56407
A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The manipulation of the argument sql leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Published 2025-09-10 · Analyzed
8.8EPSS 0.003
CVE-2025-9402
HuangDou UTCMS Config update.php server-side request forgery
Published 2025-08-25 · Analyzed
7.2EPSS 0.004
CVE-2025-9401
HuangDou UTCMS Login login.php comparison
Published 2025-08-25 · Analyzed
3.7EPSS 0.004