Known Vulnerabilities for products from Otcms
Listed below are 16 of the newest known vulnerabilities associated with the vendor "Otcms".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-30637 json | Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before... | Not Provided | 2026-03-27 | 2026-03-31 |
| CVE-2023-3241 json | A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functiona... | 7.5 - HIGH | 2023-06-14 | 2023-11-07 |
| CVE-2023-3240 json | A vulnerability has been found in OTCMS up to 6.62 and classified as problematic. Affected by this vulnerability is an unknow... | 6.5 - MEDIUM | 2023-06-14 | 2023-11-07 |
| CVE-2023-3239 json | A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of the f... | 7.5 - HIGH | 2023-06-14 | 2023-11-07 |
| CVE-2023-3238 json | A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown proces... | 9.8 - CRITICAL | 2023-06-14 | 2023-11-07 |
| CVE-2023-3237 json | A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulati... | 9.8 - CRITICAL | 2023-06-14 | 2023-11-07 |
| CVE-2023-1797 json | A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality o... | 9.8 - CRITICAL | 2023-04-02 | 2023-11-07 |
| CVE-2023-1635 json | A vulnerability was found in OTCMS 6.72. It has been declared as problematic. Affected by this vulnerability is the function ... | 6.1 - MEDIUM | 2023-03-25 | 2023-11-07 |
| CVE-2023-1634 json | A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /ad... | 9.8 - CRITICAL | 2023-03-25 | 2023-11-07 |
| CVE-2019-17370 json | OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT stateme... | 7.2 - HIGH | 2019-10-09 | 2021-07-21 |
| CVE-2019-17369 json | OTCMS v3.85 has CSRF in the admin/member_deal.php Admin Panel page, leading to creation of a new management group account, as... | 6.5 - MEDIUM | 2019-10-09 | 2019-10-16 |
| CVE-2019-13971 json | OTCMS 3.81 allows XSS via the mode parameter in an apiRun.php?mudi=autoRun request. | 6.1 - MEDIUM | 2019-07-19 | 2019-07-22 |
| CVE-2018-17364 json | OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. | 8.1 - HIGH | 2018-09-23 | 2018-11-08 |
| CVE-2018-17086 json | An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabNam... | 6.1 - MEDIUM | 2018-09-16 | 2018-11-07 |
| CVE-2018-17085 json | An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr. | 6.1 - MEDIUM | 2018-09-16 | 2018-11-07 |
| CVE-2018-8973 json | OTCMS 3.20 allows XSS by adding a keyword or link to an article, as demonstrated by an admin/keyWord_deal.php?mudi=add reques... | 6.1 - MEDIUM | 2018-03-24 | 2018-04-18 |
Known software with vulnerabilities from Otcms
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Otcms | Otcms | 3.20 |