Vulnerabilities (CVE)

Filtered by vendor Ucms Project Subscribe
Filtered by product Ucms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28443 1 Ucms Project 1 Ucms 2022-05-02 6.4 MEDIUM 9.1 CRITICAL
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
CVE-2018-17036 1 Ucms Project 1 Ucms 2022-02-20 7.5 HIGH 9.8 CRITICAL
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.
CVE-2020-25483 1 Ucms Project 1 Ucms 2021-07-21 7.5 HIGH 9.8 CRITICAL
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
CVE-2020-25537 1 Ucms Project 1 Ucms 2020-12-04 10.0 HIGH 9.8 CRITICAL
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
CVE-2018-17035 1 Ucms Project 1 Ucms 2018-11-07 7.5 HIGH 9.8 CRITICAL
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.