Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Ucms Project

First CVE: Sep 14, 2018Active for: 8 yearsTotal CVEs: 28
43.8
VTI Score
High

Ucms Project maintains a narrowly scoped content-management system that, despite its modest product footprint, occupies a position among more prominent vendors in the vulnerability landscape. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and cluster persistently around web-application input-handling and code-execution weaknesses: cross-site scripting, SQL injection, unrestricted file uploads, and code injection. These recurrent weakness classes reflect the inherent risks of user-facing web applications that process and execute dynamic content, and their tendency toward critical severity underscores the direct impact such flaws can have when exploited. Defenders should treat this vendor's advisories as high-priority, particularly those affecting internet-exposed instances; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Ucms Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2018
7 years ago
Most Recent CVE
Sep 17, 2023
1,041 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-25483CRITICAL
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
Oct 23, 20209.833NONO
CVE-2022-38297CRITICAL
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
Sep 12, 20229.831NONO
CVE-2022-35426CRITICAL
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
Aug 10, 20229.831NONO
CVE-2018-17036CRITICAL
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a
Sep 14, 20189.831NONO
CVE-2018-17035CRITICAL
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
Sep 14, 20189.830NONO
CVE-2022-28443CRITICAL
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
Apr 21, 20229.129NONO
CVE-2020-25537CRITICAL
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
Nov 30, 20209.829NONO
CVE-2022-28440HIGH
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
Apr 21, 20228.828NONO
CVE-2018-20599HIGH
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
Dec 30, 20188.828NONO
CVE-2018-17037HIGH
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
Sep 14, 20188.828NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
43%
29%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (60.7%)
Unknown0 (0.0%)
Required11 (39.3%)
Privileges Required
Low7 (25.0%)
High2 (7.1%)
None19 (67.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Ucms Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Ucms Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Ucms Project's Products

View all 2 CNAs →

Top CWEs