Ucms Project maintains a narrowly scoped content-management system that, despite its modest product footprint, occupies a position among more prominent vendors in the vulnerability landscape. Its disclosed vulnerabilities skew strongly toward critical-severity outcomes and cluster persistently around web-application input-handling and code-execution weaknesses: cross-site scripting, SQL injection, unrestricted file uploads, and code injection. These recurrent weakness classes reflect the inherent risks of user-facing web applications that process and execute dynamic content, and their tendency toward critical severity underscores the direct impact such flaws can have when exploited. Defenders should treat this vendor's advisories as high-priority, particularly those affecting internet-exposed instances; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ucms Project over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25483CRITICAL An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server. | Oct 23, 2020 | 9.8 | 33 | NO | NO |
CVE-2022-38297CRITICAL UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | Sep 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-35426CRITICAL UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | Aug 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-17036CRITICAL An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a | Sep 14, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-17035CRITICAL UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. | Sep 14, 2018 | 9.8 | 30 | NO | NO |
CVE-2022-28443CRITICAL UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | Apr 21, 2022 | 9.1 | 29 | NO | NO |
CVE-2020-25537CRITICAL File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | Nov 30, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-28440HIGH An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | Apr 21, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-20599HIGH UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. | Dec 30, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-17037HIGH user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3. | Sep 14, 2018 | 8.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ucms Project.
Media articles that mention a CVE ID that affects a product developed by Ucms Project — matched by CVE ID, not by vendor name.