Publiccms is a web content management platform that, despite a narrow product footprint, occupies a more prominent position in the vulnerability landscape than typical for vendors of comparable scope. Vulnerabilities affecting the platform skew toward serious outcomes, with an elevated share reaching critical severity, and cluster durably around web-application input-handling and file-management weaknesses including cross-site scripting, unrestricted file uploads, path traversal, and server-side request forgery. These weakness classes reflect the exposure inherent to a web-facing CMS that accepts user input and file submissions without sufficient validation and isolation. Defenders deploying this platform should prioritize input sanitization, upload controls, and access restrictions; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Publiccms over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23389CRITICAL PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter. | Feb 14, 2022 | 9.8 | 41 | NO | NO |
CVE-2020-20914CRITICAL SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter. | Apr 4, 2023 | 9.8 | 31 | NO | NO |
CVE-2021-27693CRITICAL Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage. | Sep 2, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-12914CRITICAL A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After a | Jun 27, 2018 | 9.8 | 31 | NO | NO |
CVE-2025-69437HIGH PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass PDF security checks in the backend CmsFileUtils.java. If a u | Feb 27, 2026 | 8.7 | 30 | NO | NO |
CVE-2020-20915CRITICAL SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl. | Apr 4, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-40881CRITICAL An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code. | Sep 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2026-3289CRITICAL A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Gener | Feb 27, 2026 | 9.8 | 29 | NO | NO |
CVE-2018-11500HIGH An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin a | May 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2026-1112HIGH A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeA | Jan 18, 2026 | 8.1 | 26 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Publiccms.
Media articles that mention a CVE ID that affects a product developed by Publiccms — matched by CVE ID, not by vendor name.