publiccms records
47 published records for vendor publiccms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-434 Unrestricted Upload of File with Dangerous Type9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-918 Server-Side Request Forgery (SSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
47 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2022-23389No exploit | PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.publiccms · publiccms · CWE-78 | Critical9.8 | — | 22.0% | Feb 14, 2022 |
40Plan | CVE-2018-12914No exploit | A remote code execution issue was discovered in PublicCMS V4.0.20180210.publiccms · publiccms · CWE-434 | Critical9.8 | — | 3.9% | Jun 27, 2018 |
39Monitor | CVE-2021-40881No exploit | An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.publiccms · publiccms | Critical9.8 | — | 1.6% | Sep 15, 2021 |
39Monitor | CVE-2023-46990No exploit | Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to thepubliccms · publiccms · CWE-502 | Critical9.8 | — | 1.5% | Nov 20, 2023 |
39Monitor | CVE-2020-20914No exploit | SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.publiccms · publiccms · CWE-89 | Critical9.8 | — | 1.1% | Apr 4, 2023 |
39Monitor | CVE-2020-20915No exploit | SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSitepubliccms · publiccms · CWE-89 | Critical9.8 | — | 1.1% | Apr 4, 2023 |
39Monitor | CVE-2021-27693No exploit | Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimagepubliccms · publiccms · CWE-918 | Critical9.8 | — | 1.1% | Sep 2, 2022 |
39Monitor | CVE-2023-34852Proof of concept | PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.publiccms · publiccms · CWE-732 | Critical9.8 | — | 1.0% | Jun 15, 2023 |
39Monitor | CVE-2025-25361No exploit | An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to exepubliccms · publiccms · CWE-434 | Critical9.8 | — | 0.7% | Mar 6, 2025 |
36Monitor | CVE-2025-65836No exploit | PublicCMS V5.202506.b is vulnerable to SSRF.publiccms · publiccms · CWE-918 | Critical9.1 | — | 0.3% | Dec 1, 2025 |
35Monitor | CVE-2024-40550No exploit | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers tpubliccms · publiccms · CWE-434 | High8.8 | — | 1.0% | Jul 12, 2024 |
35Monitor | CVE-2024-31759No exploit | An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.publiccms · publiccms · CWE-284 | High8.8 | — | 0.9% | Apr 16, 2024 |
35Monitor | CVE-2024-40546No exploit | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrpubliccms · publiccms · CWE-434 | High8.8 | — | 0.7% | Jul 12, 2024 |
35Monitor | CVE-2024-40552No exploit | PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/Scriptpubliccms · publiccms · CWE-94 | High8.8 | — | 0.7% | Jul 12, 2024 |
35Monitor | CVE-2024-40548No exploit | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitpubliccms · publiccms · CWE-434 | High8.8 | — | 0.7% | Jul 12, 2024 |
35Monitor | CVE-2024-40549No exploit | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute publiccms · publiccms · CWE-434 | High8.8 | — | 0.7% | Jul 12, 2024 |
35Monitor | CVE-2024-40545No exploit | An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arpubliccms · publiccms · CWE-434 | High8.8 | — | 0.7% | Jul 12, 2024 |
35Monitor | CVE-2018-11500No exploit | An issue was discovered in PublicCMS V4.0.20180210.publiccms · publiccms · CWE-352 | High8.8 | — | 0.6% | May 26, 2018 |
35Monitor | CVE-2024-40544No exploit | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.publiccms · publiccms · CWE-918 | High8.8 | — | 0.5% | Jul 12, 2024 |
35Monitor | CVE-2024-40551No exploit | An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute apubliccms · publiccms · CWE-434 | High8.8 | — | 0.4% | Jul 12, 2024 |
35Monitor | CVE-2024-40543No exploit | PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.publiccms · publiccms · CWE-918 | High8.8 | — | 0.3% | Jul 12, 2024 |
35Monitor | CVE-2025-65840No exploit | PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.publiccms · publiccms · CWE-352 | High8.8 | — | 0.2% | Dec 1, 2025 |
34Monitor | CVE-2025-69437No exploit | PublicCMS v5.202506.d and earlier is vulnerable to stored XSS.publiccms · publiccms · CWE-79 | High8.7 | — | 0.4% | Feb 27, 2026 |
32Monitor | CVE-2025-57516No exploit | OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary compubliccms · publiccms · CWE-78 | High8.2 | — | 1.1% | Sep 29, 2025 |
30Monitor | CVE-2025-65838No exploit | PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.publiccms · publiccms · CWE-22 | High7.5 | — | 0.4% | Dec 1, 2025 |
- CVE-2022-2338946Plan
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
CriticalCVSS 9.8No exploitEPSS 22%publiccms · publiccmsFeb 14, 2022
- CVE-2018-1291440Plan
A remote code execution issue was discovered in PublicCMS V4.0.20180210.
CriticalCVSS 9.8No exploitEPSS 4%publiccms · publiccmsJun 27, 2018
- CVE-2021-4088139Monitor
An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 2%publiccms · publiccmsSep 15, 2021
- CVE-2023-4699039Monitor
Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the
CriticalCVSS 9.8No exploitEPSS 1%publiccms · publiccmsNov 20, 2023
- CVE-2020-2091439Monitor
SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.
CriticalCVSS 9.8No exploitEPSS 1%publiccms · publiccmsApr 4, 2023
- CVE-2020-2091539Monitor
SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSite
CriticalCVSS 9.8No exploitEPSS 1%publiccms · publiccmsApr 4, 2023
- CVE-2021-2769339Monitor
Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage
CriticalCVSS 9.8No exploitEPSS 1%publiccms · publiccmsSep 2, 2022
- CVE-2023-3485239Monitor
PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.
CriticalCVSS 9.8Proof of conceptEPSS 1%publiccms · publiccmsJun 15, 2023
- CVE-2025-2536139Monitor
An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to exe
CriticalCVSS 9.8No exploitEPSS 1%publiccms · publiccmsMar 6, 2025
- CVE-2025-6583636Monitor
PublicCMS V5.202506.b is vulnerable to SSRF.
CriticalCVSS 9.1No exploitEPSS 0%publiccms · publiccmsDec 1, 2025
- CVE-2024-4055035Monitor
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers t
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsJul 12, 2024
- CVE-2024-3175935Monitor
An issue in sanluan PublicCMS v.4.0.202302.e allows an attacker to escalate privileges via the change password function.
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsApr 16, 2024
- CVE-2024-4054635Monitor
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitr
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsJul 12, 2024
- CVE-2024-4055235Monitor
PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/Script
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsJul 12, 2024
- CVE-2024-4054835Monitor
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbit
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsJul 12, 2024
- CVE-2024-4054935Monitor
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsJul 12, 2024
- CVE-2024-4054535Monitor
An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute ar
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsJul 12, 2024
- CVE-2018-1150035Monitor
An issue was discovered in PublicCMS V4.0.20180210.
HighCVSS 8.8No exploitEPSS 1%publiccms · publiccmsMay 26, 2018
- CVE-2024-4054435Monitor
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.
HighCVSS 8.8No exploitEPSS 0%publiccms · publiccmsJul 12, 2024
- CVE-2024-4055135Monitor
An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute a
HighCVSS 8.8No exploitEPSS 0%publiccms · publiccmsJul 12, 2024
- CVE-2024-4054335Monitor
PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.
HighCVSS 8.8No exploitEPSS 0%publiccms · publiccmsJul 12, 2024
- CVE-2025-6584035Monitor
PublicCMS V5.202506.b is vulnerable to Cross Site Request Forgery (CSRF) in the CkEditorAdminController.
HighCVSS 8.8No exploitEPSS 0%publiccms · publiccmsDec 1, 2025
- CVE-2025-6943734Monitor
PublicCMS v5.202506.d and earlier is vulnerable to stored XSS.
HighCVSS 8.7No exploitEPSS 0%publiccms · publiccmsFeb 27, 2026
- CVE-2025-5751632Monitor
OS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary com
HighCVSS 8.2No exploitEPSS 1%publiccms · publiccmsSep 29, 2025
- CVE-2025-6583830Monitor
PublicCMS V5.202506.b is vulnerable to path traversal via the doUploadSitefile method.
HighCVSS 7.5No exploitEPSS 0%publiccms · publiccmsDec 1, 2025