📦 Ujcms

by Ujcms

🔍 What is Ujcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2023-51350

CRITICAL CVSS 9.8 Jan 11, 2024

This vulnerability in ujcms v8.0.2 allows remote attackers to spoof IP addresses via the X-Forwarded-For header, potentially leading to information disclosure and arbitrary code execution. Any organiz...

CVE-2023-34747

CRITICAL CVSS 9.8 Jun 14, 2023

This CVE describes a critical file upload vulnerability in ujcms 6.0.2 that allows attackers to upload arbitrary files, including malicious scripts, via the /api/backend/core/web-file-upload/upload en...

CVE-2023-34865

CRITICAL CVSS 9.8 Jun 14, 2023

A directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files to arbitrary locations on the server via the rename feature. This affects all ujcms 6.0.2 installations with the vulne...

CVE-2026-2954

MEDIUM CVSS 6.3 Feb 22, 2026

This vulnerability allows remote attackers to perform injection attacks via manipulated driverClassName/url parameters in Dromara UJCMS's importChanel function. Attackers can potentially execute arbit...

CVE-2024-55452

MEDIUM CVSS 5.4 Dec 16, 2024

This vulnerability allows authenticated attackers in UJCMS 9.6.3 to create malicious block/carousel items that redirect users to attacker-controlled websites. When users click these items, they can be...