Known Vulnerabilities for Ucms by Ucms Project
Listed below are 10 of the newest known vulnerabilities associated with "Ucms" by "Ucms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2023-5015 json | A vulnerability was found in UCMS 1.4.7. It has been classified as problematic. Affected is an unknown function of the file a... | 6.1 - MEDIUM | 2023-09-17 | 2023-11-07 |
| CVE-2023-2294 json | A vulnerability was found in UCMS 1.6.0. It has been classified as problematic. This affects an unknown part of the file sadd... | 6.1 - MEDIUM | 2023-04-26 | 2023-11-07 |
| CVE-2023-1303 json | A vulnerability was found in UCMS 1.6 and classified as critical. This issue affects some unknown processing of the file sadm... | 9.8 - CRITICAL | 2023-03-09 | 2023-11-07 |
| CVE-2022-42234 json | There is a file inclusion vulnerability in the template management module in UCMS 1.6 | 8.8 - HIGH | 2022-10-14 | 2022-10-17 |
| CVE-2022-38527 json | UCMS v1.6.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Import function under the Site Manag... | 6.1 - MEDIUM | 2022-09-19 | 2022-09-22 |
| CVE-2022-38297 json | UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | 9.8 - CRITICAL | 2022-09-12 | 2022-09-15 |
| CVE-2022-35426 json | UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | 9.8 - CRITICAL | 2022-08-10 | 2022-08-12 |
| CVE-2022-28444 json | UCMS v1.6 was discovered to contain an arbitrary file read vulnerability. | 7.5 - HIGH | 2022-04-21 | 2022-05-02 |
| CVE-2022-28443 json | UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | 9.1 - CRITICAL | 2022-04-21 | 2022-05-02 |
| CVE-2022-28440 json | An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | 8.8 - HIGH | 2022-04-21 | 2022-05-02 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Ucms Project | Ucms | 1.5.0 | |||
| Application | Ucms Project | Ucms | 1.4.8 | |||
| Application | Ucms Project | Ucms | 1.4.7 | |||
| Application | Ucms Project | Ucms | 1.4.6 | |||
| Application | Ucms Project | Ucms | 1.4.5 | |||
| Application | Ucms Project | Ucms | 1.4.4 | |||
| Application | Ucms Project | Ucms | 1.4.3 | |||
| Application | Ucms Project | Ucms | 1.4.2 | |||
| Application | Ucms Project | Ucms | 1.4.1 | |||
| Application | Ucms Project | Ucms | 1.4.0 | |||
| Application | Ucms Project | Ucms | 1.3.9 | |||
| Application | Ucms Project | Ucms | 1.3.8 | |||
| Application | Ucms Project | Ucms | 1.3.7 | |||
| Application | Ucms Project | Ucms | 1.3.6 | |||
| Application | Ucms Project | Ucms | 1.3.5 | |||
| Application | Ucms Project | Ucms | 1.3.4 | |||
| Application | Ucms Project | Ucms | 1.3.3 | |||
| Application | Ucms Project | Ucms | 1.3.2 | |||
| Application | Ucms Project | Ucms | 1.3.1 | |||
| Application | Ucms Project | Ucms | 1.3 |