📦 Publiccms

by Publiccms

🔍 What is Publiccms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-65836

CRITICAL CVSS 9.1 Dec 1, 2025

PublicCMS V5.202506.b contains a Server-Side Request Forgery (SSRF) vulnerability in the chat interface of SimpleAiAdminController. This allows attackers to make unauthorized requests to internal syst...

CVE-2025-25361

CRITICAL CVSS 9.8 Mar 6, 2025

This vulnerability allows attackers to upload malicious SVG or XML files to PublicCMS v4.0.202406, potentially leading to remote code execution. Attackers can exploit the /cms/CmsWebFileAdminControlle...

CVE-2023-34852

CRITICAL CVSS 9.8 Jun 15, 2023

PublicCMS versions up to V4.0.202302 have insecure permissions that allow attackers to bypass authentication and gain unauthorized access. This affects all users running vulnerable versions of PublicC...

CVE-2020-20915

CRITICAL CVSS 9.8 Apr 4, 2023

This is a critical SQL injection vulnerability in PublicCMS v4.0 that allows remote attackers to execute arbitrary SQL commands via the sql parameter in SysSiteAdminControl. Attackers can potentially ...

CVE-2022-23389

CRITICAL CVSS 9.8 Feb 14, 2022

PublicCMS v4.0 contains a remote code execution vulnerability via the cmdarray parameter that allows attackers to execute arbitrary commands on the server. This affects all deployments of PublicCMS v4...

CVE-2021-40881

CRITICAL CVSS 9.8 Sep 15, 2021

This vulnerability in PublicCMS v4.0 allows attackers to execute arbitrary code through BAT file parameter manipulation. It affects all systems running the vulnerable version of PublicCMS. Attackers c...

CVE-2025-65840

HIGH CVSS 8.8 Dec 1, 2025

PublicCMS V5.202506.b contains a CSRF vulnerability in the CkEditorAdminController that allows attackers to trick authenticated administrators into performing unauthorized actions. This affects all us...

CVE-2025-65838

HIGH CVSS 7.5 Dec 1, 2025

PublicCMS V5.202506.b contains a path traversal vulnerability in the doUploadSitefile method that allows attackers to write arbitrary files to unintended directories. This affects all systems running ...

CVE-2024-42523

HIGH CVSS 7.2 Aug 23, 2024

PublicCMS versions up to V4.0.202302.e contain an unrestricted file upload vulnerability in the template metadata management endpoint. This allows authenticated attackers to upload arbitrary files, po...

CVE-2024-40543

HIGH CVSS 8.8 Jul 12, 2024

PublicCMS v4.0.202302.e contains a Server-Side Request Forgery vulnerability in the UEditor component's image capture functionality. This allows attackers to make the server send arbitrary HTTP reques...

CVE-2024-40545

HIGH CVSS 8.8 Jul 12, 2024

This vulnerability allows attackers to upload malicious files to the PublicCMS administration interface, leading to remote code execution. It affects PublicCMS v4.0.202302.e installations with the vul...

CVE-2024-40548

HIGH CVSS 8.8 Jul 12, 2024

This vulnerability allows attackers to upload malicious files to the PublicCMS admin interface, leading to remote code execution. Any organization running PublicCMS v4.0.202302.e is affected. Attacker...

CVE-2024-40550

HIGH CVSS 8.8 Jul 12, 2024

This vulnerability allows attackers to upload arbitrary files to the Public CMS admin interface, which can lead to remote code execution. It affects Public CMS v.4.0.202302.e installations with the vu...

CVE-2024-40552

HIGH CVSS 8.8 Jul 12, 2024

PublicCMS v4.0.202302.e contains a remote code execution vulnerability in the ScriptComponent.java file via the cmdarray parameter. This allows attackers to execute arbitrary commands on the server wi...

CVE-2024-31759

HIGH CVSS 8.8 Apr 16, 2024

This vulnerability in sanluan PublicCMS v4.0.202302.e allows attackers to escalate privileges through the change password function. Attackers can gain administrative access by exploiting insufficient ...

CVE-2026-2010

MEDIUM CVSS 4.2 Feb 6, 2026

This CVE describes an improper authorization vulnerability in Sanluan PublicCMS's trade payment handler. Attackers can manipulate payment IDs to bypass authorization checks, potentially accessing unau...

CVE-2026-1112

MEDIUM CVSS 5.4 Jan 18, 2026

This CVE describes an improper authorization vulnerability in Sanluan PublicCMS's trade address deletion endpoint. Attackers can remotely manipulate the 'ids' parameter to delete trade addresses witho...

CVE-2026-1111

MEDIUM CVSS 4.7 Jan 18, 2026

This CVE describes a path traversal vulnerability in Sanluan PublicCMS that allows attackers to write files to arbitrary locations on the server. The vulnerability affects PublicCMS installations up t...

CVE-2025-65837

MEDIUM CVSS 5.4 Dec 22, 2025

PublicCMS V5.202506.b contains a cross-site scripting (XSS) vulnerability in its Content Search module. This allows attackers to inject malicious scripts that execute in users' browsers when they inte...

CVE-2024-46410

MEDIUM CVSS 4.8 Oct 8, 2024

PublicCMS V4.0.202406.d contains a stored cross-site scripting (XSS) vulnerability in the Category Management feature. Attackers can inject malicious scripts that execute when administrators view or m...

CVE-2024-40547

MEDIUM CVSS 6.5 Jul 12, 2024

PublicCMS v4.0.202302.e contains an arbitrary file content replacement vulnerability in the /admin/cmsTemplate/replace component. This allows authenticated attackers with admin access to modify any fi...