ujcms records
20 published records for vendor ujcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-290 Authentication Bypass by Spoofing1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
20 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2023-34747No exploit | File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.ujcms · ujcms · CWE-434 | Critical9.8 | — | 20.0% | Jun 14, 2023 |
43Plan | CVE-2022-23329No exploit | A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands viaujcms · jspxcms · CWE-434 | Critical9.8 | — | 14.4% | Feb 4, 2022 |
39Monitor | CVE-2023-51350No exploit | A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script ujcms · ujcms · CWE-290 | Critical9.8 | — | 1.3% | Jan 11, 2024 |
39Monitor | CVE-2023-34865No exploit | Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.ujcms · ujcms · CWE-22 | Critical9.8 | — | 1.2% | Jun 14, 2023 |
30Monitor | CVE-2023-34878No exploit | An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-hujcms · ujcms · CWE-203 | High7.5 | — | 0.7% | Jun 14, 2023 |
26Monitor | CVE-2024-12483Proof of concept | Dromara UJCMS User ID id authorizationujcms · ujcms · CWE-285 | Medium6.3 | — | 3.6% | Dec 11, 2024 |
26Monitor | CVE-2022-28090No exploit | Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.ujcms · jspxcms · CWE-918 | Medium6.5 | — | 1.1% | May 4, 2022 |
26Monitor | CVE-2023-3231No exploit | UJCMS ZIP Package information disclosureujcms · ujcms · CWE-200 | Medium6.5 | — | 0.8% | Jun 14, 2023 |
24Monitor | CVE-2024-1257No exploit | Jspxcms find_text.do cross site scriptingujcms · jspxcms · CWE-79 | Medium6.1 | — | 0.5% | Feb 6, 2024 |
24Monitor | CVE-2023-24369No exploit | A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a craftedujcms · ujcms · CWE-79 | Medium6.1 | — | 0.4% | Feb 17, 2023 |
21Monitor | CVE-2023-51806No exploit | File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.ujcms · ujcms · CWE-434 | Medium5.4 | — | 0.6% | Jan 12, 2024 |
21Monitor | CVE-2024-0599No exploit | Jspxcms Document Management Page InfoController.java cross site scriptingujcms · jspxcms · CWE-79 | Medium5.4 | — | 0.5% | Jan 16, 2024 |
21Monitor | CVE-2024-55452No exploit | A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carouselujcms · ujcms · CWE-601 | Medium5.4 | — | 0.3% | Dec 16, 2024 |
20Monitor | CVE-2025-25772No exploit | A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add Aujcms · jspxcms · CWE-352 | Medium5.1 | — | 0.2% | Feb 21, 2025 |
19Monitor | CVE-2025-2491No exploit | Dromara ujcms Edit Template File Page WebFileTemplateController.java update cross site scriptingujcms · ujcms · CWE-79 | Medium4.8 | — | 0.3% | Mar 18, 2025 |
19Monitor | CVE-2025-2490No exploit | Dromara ujcms File Upload WebFileUploadController.java upload cross site scriptingujcms · ujcms · CWE-79 | Medium4.8 | — | 0.3% | Mar 18, 2025 |
19Monitor | CVE-2024-55451No exploit | A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3.ujcms · ujcms · CWE-79 | Medium4.8 | — | 0.3% | Dec 16, 2024 |
17Monitor | CVE-2024-1256No exploit | Jspxcms filter_text.do cross site scriptingujcms · jspxcms · CWE-79 | Medium4.3 | — | 0.6% | Feb 6, 2024 |
8Monitor | CVE-2026-2953No exploit | Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversalujcms · ujcms · CWE-22 | Low2.1 | — | 1.0% | Feb 22, 2026 |
8Monitor | CVE-2026-2954No exploit | Dromara UJCMS ImportDataController import-channel importChanel injectionujcms · ujcms · CWE-74 | Low2.1 | — | 0.7% | Feb 22, 2026 |
- CVE-2023-3474745Plan
File upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.
CriticalCVSS 9.8No exploitEPSS 20%ujcms · ujcmsJun 14, 2023
- CVE-2022-2332943Plan
A vulnerability in ${"freemarker.template.utility.Execute"?new() of UJCMS Jspxcms v10.2.0 allows attackers to execute arbitrary commands via
CriticalCVSS 9.8No exploitEPSS 14%ujcms · jspxcmsFeb 4, 2022
- CVE-2023-5135039Monitor
A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script
CriticalCVSS 9.8No exploitEPSS 1%ujcms · ujcmsJan 11, 2024
- CVE-2023-3486539Monitor
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
CriticalCVSS 9.8No exploitEPSS 1%ujcms · ujcmsJun 14, 2023
- CVE-2023-3487830Monitor
An issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-h
HighCVSS 7.5No exploitEPSS 1%ujcms · ujcmsJun 14, 2023
- CVE-2024-1248326Monitor
Dromara UJCMS User ID id authorization
MediumCVSS 6.3Proof of conceptEPSS 4%ujcms · ujcmsDec 11, 2024
- CVE-2022-2809026Monitor
Jspxcms v10.2.0 allows attackers to execute a Server-Side Request Forgery (SSRF) via /cmscp/ext/collect/fetch_url.do?url=.
MediumCVSS 6.5No exploitEPSS 1%ujcms · jspxcmsMay 4, 2022
- CVE-2023-323126Monitor
UJCMS ZIP Package information disclosure
MediumCVSS 6.5No exploitEPSS 1%ujcms · ujcmsJun 14, 2023
- CVE-2024-125724Monitor
Jspxcms find_text.do cross site scripting
MediumCVSS 6.1No exploitEPSS 0%ujcms · jspxcmsFeb 6, 2024
- CVE-2023-2436924Monitor
A cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted
MediumCVSS 6.1No exploitEPSS 0%ujcms · ujcmsFeb 17, 2023
- CVE-2023-5180621Monitor
File Upload vulnerability in Ujcms v.8.0.2 allows a local attacker to execute arbitrary code via a crafted file.
MediumCVSS 5.4No exploitEPSS 1%ujcms · ujcmsJan 12, 2024
- CVE-2024-059921Monitor
Jspxcms Document Management Page InfoController.java cross site scripting
MediumCVSS 5.4No exploitEPSS 1%ujcms · jspxcmsJan 16, 2024
- CVE-2024-5545221Monitor
A URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel
MediumCVSS 5.4No exploitEPSS 0%ujcms · ujcmsDec 16, 2024
- CVE-2025-2577220Monitor
A Cross-Site Request Forgery (CSRF) in the component /back/UserController.java of Jspxcms v9.0 to v9.5 allows attackers to arbitrarily add A
MediumCVSS 5.1No exploitEPSS 0%ujcms · jspxcmsFeb 21, 2025
- CVE-2025-249119Monitor
Dromara ujcms Edit Template File Page WebFileTemplateController.java update cross site scripting
MediumCVSS 4.8No exploitEPSS 0%ujcms · ujcmsMar 18, 2025
- CVE-2025-249019Monitor
Dromara ujcms File Upload WebFileUploadController.java upload cross site scripting
MediumCVSS 4.8No exploitEPSS 0%ujcms · ujcmsMar 18, 2025
- CVE-2024-5545119Monitor
A Stored Cross-Site Scripting (XSS) vulnerability exists in authenticated SVG file upload and viewing functionality in UJCMS 9.6.3.
MediumCVSS 4.8No exploitEPSS 0%ujcms · ujcmsDec 16, 2024
- CVE-2024-125617Monitor
Jspxcms filter_text.do cross site scripting
MediumCVSS 4.3No exploitEPSS 1%ujcms · jspxcmsFeb 6, 2024
- CVE-2026-29538Monitor
Dromara UJCMS Template WebFileTemplateController.delete deleteDirectory path traversal
LowCVSS 2.1No exploitEPSS 1%ujcms · ujcmsFeb 22, 2026
- CVE-2026-29548Monitor
Dromara UJCMS ImportDataController import-channel importChanel injection
LowCVSS 2.1No exploitEPSS 1%ujcms · ujcmsFeb 22, 2026