Ofcms Project maintains a content-management system product that, despite modest representation in the broader vulnerability landscape, sits among more prominent entities when assessed within its application category. The recurring vulnerability profile centers on a concentrated set of web-application input-handling and file-management weakness classes: unrestricted file uploads, cross-site scripting, code injection, path traversal, and SQL injection—the signature classes of content-management platforms where user input flows through dynamic content generation and database layers. These patterns reflect the structural demands of a web-facing CMS architecture where serialization, sanitization, and access boundaries are the primary defensive concerns. Defenders tracking this product should prioritize input-validation patches and restrict administrative upload functionality in internet-exposed deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ofcms Project over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24760HIGH An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController. | Mar 16, 2023 | 8.8 | 27 | NO | NO |
CVE-2024-34256CRITICAL OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function. | May 14, 2024 | 9.8 | 25 | NO | NO |
CVE-2019-9609HIGH An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA | Mar 6, 2019 | 8.8 | 25 | NO | NO |
CVE-2022-29653MEDIUM OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json. | Jun 2, 2022 | 6.1 | 22 | NO | NO |
CVE-2019-9617HIGH An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA | Mar 6, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-9614HIGH An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' | Mar 6, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-9612HIGH An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA | Mar 6, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-9611MEDIUM An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary co | Mar 6, 2019 | 6.5 | 22 | NO | NO |
CVE-2019-9608HIGH An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA | Mar 6, 2019 | 8.8 | 22 | NO | NO |
CVE-2022-27961MEDIUM A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the | Apr 10, 2022 | 5.4 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ofcms Project.
Media articles that mention a CVE ID that affects a product developed by Ofcms Project — matched by CVE ID, not by vendor name.