Otcms develops a web content management system that sits as a core application in publishing and editorial workflows, placing it in a prominent position within infrastructure despite a narrow product scope. The vendor's vulnerability profile skews toward serious outcomes, with an elevated share reaching critical severity, and the durable signal centers on application-layer input-handling and access-control weaknesses including cross-site scripting, SQL injection, server-side request forgery, path traversal, and race conditions that are characteristic of web platforms with complex request processing. Current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Otcms over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-1797CRITICAL A vulnerability classified as critical was found in OTCMS 6.0.1. Affected by this vulnerability is an unknown functionality of the file sysCheckFile.php?mudi=sql. The manipulation | Apr 2, 2023 | 9.8 | 31 | NO | NO |
CVE-2023-1634CRITICAL A vulnerability was found in OTCMS 6.72. It has been classified as critical. Affected is the function UseCurl of the file /admin/info_deal.php of the component URL Parameter Handle | Mar 25, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-3238CRITICAL A vulnerability, which was classified as critical, has been found in OTCMS up to 6.62. This issue affects some unknown processing of the file /admin/read.php?mudi=getSignal. The ma | Jun 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-3237CRITICAL A vulnerability classified as critical was found in OTCMS up to 6.62. This vulnerability affects unknown code. The manipulation of the argument username/password with the input adm | Jun 14, 2023 | 9.8 | 27 | NO | NO |
CVE-2026-30637HIGH Server-Side Request Forgery (SSRF) vulnerability exists in the AnnounContent of the /admin/read.php in OTCMS V7.66 and before. The vulnerability allows remote attackers to craft HT | Mar 27, 2026 | 7.5 | 26 | NO | NO |
CVE-2018-17364HIGH OTCMS 3.61 allows remote attackers to execute arbitrary PHP code via the accBackupDir parameter. | Sep 23, 2018 | 8.1 | 26 | NO | NO |
CVE-2023-3241HIGH A vulnerability was found in OTCMS up to 6.62 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/read.php?mudi=announContent. Th | Jun 14, 2023 | 7.5 | 23 | NO | NO |
CVE-2019-17370HIGH OTCMS v3.85 allows arbitrary PHP Code Execution because admin/sysCheckFile_deal.php blocks "into outfile" in a SELECT statement, but does not block the "into/**/outfile" manipulati | Oct 9, 2019 | 7.2 | 23 | NO | NO |
CVE-2023-3239HIGH A vulnerability, which was classified as problematic, was found in OTCMS up to 6.62. Affected is an unknown function of the file admin/readDeal.php?mudi=readQrCode. The manipulatio | Jun 14, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-1635MEDIUM A vulnerability was found in OTCMS 6.72. It has been declared as problematic. Affected by this vulnerability is the function AutoRun of the file apiRun.php. The manipulation of the | Mar 25, 2023 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Otcms.
Media articles that mention a CVE ID that affects a product developed by Otcms — matched by CVE ID, not by vendor name.