Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Ucms Project Subscribe
Filtered by product Ucms
Total 26 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-20599 1 Ucms Project 1 Ucms 2019-01-04 6.5 MEDIUM 8.8 HIGH
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
CVE-2018-20600 1 Ucms Project 1 Ucms 2019-01-04 4.3 MEDIUM 6.1 MEDIUM
sadmin\cedit.php in UCMS 1.4.7 has XSS via an index.php sadmin_cedit action.
CVE-2018-20601 1 Ucms Project 1 Ucms 2019-01-04 3.5 LOW 4.8 MEDIUM
UCMS 1.4.7 has XSS via the description parameter in an index.php list_editpost action.
CVE-2018-17320 1 Ucms Project 1 Ucms 2018-11-13 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.
CVE-2018-17034 1 Ucms Project 1 Ucms 2018-11-07 4.3 MEDIUM 6.1 MEDIUM
UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.
CVE-2018-17035 1 Ucms Project 1 Ucms 2018-11-07 7.5 HIGH 9.8 CRITICAL
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.