otcms records
18 published records for vendor otcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-24 Path Traversal: '../filedir'2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
18 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2023-3237No exploit | OTCMS hard-coded passwordotcms · otcms · CWE-259 | Critical9.8 | — | 0.9% | Jun 14, 2023 |
39Monitor | CVE-2023-1797No exploit | OTCMS unrestricted uploadotcms · otcms · CWE-434 | Critical9.8 | — | 0.9% | Apr 2, 2023 |
39Monitor | CVE-2023-1634No exploit | OTCMS URL Parameter info_deal.php UseCurl server-side request forgeryotcms · otcms · CWE-918 | Critical9.8 | — | 0.7% | Mar 25, 2023 |
39Monitor | CVE-2023-3238No exploit | OTCMS server-side request forgeryotcms · otcms · CWE-918 | Critical9.8 | — | 0.7% | Jun 14, 2023 |
32Monitor | CVE-2018-17364No exploit | OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.otcms · otcms · CWE-94 | High8.1 | — | 0.9% | Sep 23, 2018 |
30Monitor | CVE-2023-3239No exploit | OTCMS path traversalotcms · otcms · CWE-24 | High7.5 | — | 1.0% | Jun 14, 2023 |
30Monitor | CVE-2023-3241No exploit | OTCMS path traversalotcms · otcms · CWE-22 | High7.5 | — | 1.0% | Jun 14, 2023 |
30Monitor | CVE-2026-30637No exploit | Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before.otcms · otcms · CWE-918 | High7.5 | — | 0.6% | Mar 27, 2026 |
29Monitor | CVE-2019-17370No exploit | OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does nootcms · otcms · CWE-89 | High7.2 | — | 2.1% | Oct 9, 2019 |
28Monitor | CVE-2023-6772No exploit | OTCMS ind_backstage.php sql injectionotcms · otcms · CWE-89 | High7.2 | — | 0.6% | Dec 13, 2023 |
26Monitor | CVE-2023-3240No exploit | OTCMS usersNews_deal.php path traversalotcms · otcms · CWE-24 | Medium6.5 | — | 1.0% | Jun 14, 2023 |
26Monitor | CVE-2019-17369No exploit | OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated botcms · otcms · CWE-352 | Medium6.5 | — | 0.5% | Oct 9, 2019 |
24Monitor | CVE-2019-13971No exploit | OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.otcms · otcms · CWE-79 | Medium6.1 | — | 0.8% | Jul 19, 2019 |
24Monitor | CVE-2018-17085No exploit | An issue was discovered in OTCMS 3.61.otcms · otcms · CWE-79 | Medium6.1 | — | 0.7% | Sep 16, 2018 |
24Monitor | CVE-2018-17086No exploit | An issue was discovered in OTCMS 3.61.otcms · otcms · CWE-79 | Medium6.1 | — | 0.7% | Sep 16, 2018 |
24Monitor | CVE-2018-8973No exploit | OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.otcms · otcms · CWE-79 | Medium6.1 | — | 0.7% | Mar 24, 2018 |
24Monitor | CVE-2023-1635No exploit | OTCMS apiRun.php AutoRun cross site scriptingotcms · otcms · CWE-79 | Medium6.1 | — | 0.6% | Mar 25, 2023 |
17Monitor | CVE-2024-57252No exploit | OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.otcms · otcms · CWE-918 | Medium4.3 | — | 0.3% | Jan 17, 2025 |
- CVE-2023-323739Monitor
OTCMS hard-coded password
CriticalCVSS 9.8No exploitEPSS 1%otcms · otcmsJun 14, 2023
- CVE-2023-179739Monitor
OTCMS unrestricted upload
CriticalCVSS 9.8No exploitEPSS 1%otcms · otcmsApr 2, 2023
- CVE-2023-163439Monitor
OTCMS URL Parameter info_deal.php UseCurl server-side request forgery
CriticalCVSS 9.8No exploitEPSS 1%otcms · otcmsMar 25, 2023
- CVE-2023-323839Monitor
OTCMS server-side request forgery
CriticalCVSS 9.8No exploitEPSS 1%otcms · otcmsJun 14, 2023
- CVE-2018-1736432Monitor
OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter.
HighCVSS 8.1No exploitEPSS 1%otcms · otcmsSep 23, 2018
- CVE-2023-323930Monitor
OTCMS path traversal
HighCVSS 7.5No exploitEPSS 1%otcms · otcmsJun 14, 2023
- CVE-2023-324130Monitor
OTCMS path traversal
HighCVSS 7.5No exploitEPSS 1%otcms · otcmsJun 14, 2023
- CVE-2026-3063730Monitor
Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before.
HighCVSS 7.5No exploitEPSS 1%otcms · otcmsMar 27, 2026
- CVE-2019-1737029Monitor
OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does no
HighCVSS 7.2No exploitEPSS 2%otcms · otcmsOct 9, 2019
- CVE-2023-677228Monitor
OTCMS ind_backstage.php sql injection
HighCVSS 7.2No exploitEPSS 1%otcms · otcmsDec 13, 2023
- CVE-2023-324026Monitor
OTCMS usersNews_deal.php path traversal
MediumCVSS 6.5No exploitEPSS 1%otcms · otcmsJun 14, 2023
- CVE-2019-1736926Monitor
OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as demonstrated b
MediumCVSS 6.5No exploitEPSS 1%otcms · otcmsOct 9, 2019
- CVE-2019-1397124Monitor
OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request.
MediumCVSS 6.1No exploitEPSS 1%otcms · otcmsJul 19, 2019
- CVE-2018-1708524Monitor
An issue was discovered in OTCMS 3.61.
MediumCVSS 6.1No exploitEPSS 1%otcms · otcmsSep 16, 2018
- CVE-2018-1708624Monitor
An issue was discovered in OTCMS 3.61.
MediumCVSS 6.1No exploitEPSS 1%otcms · otcmsSep 16, 2018
- CVE-2018-897324Monitor
OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add request.
MediumCVSS 6.1No exploitEPSS 1%otcms · otcmsMar 24, 2018
- CVE-2023-163524Monitor
OTCMS apiRun.php AutoRun cross site scripting
MediumCVSS 6.1No exploitEPSS 1%otcms · otcmsMar 25, 2023
- CVE-2024-5725217Monitor
OtCMS <=V7.46 is vulnerable to Server-Side Request Forgery (SSRF) in /admin/read.php, which can Read system files arbitrarily.
MediumCVSS 4.3No exploitEPSS 0%otcms · otcmsJan 17, 2025