Ucms
Vendor:
First CVE: Sep 14, 2018 · Active for 7 years
28
Total CVEs
More Total CVEs than 96% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ucms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2018
7 years ago
Most Recent CVE
Sep 17, 2023
1,040 days ago
CVE Severity & Scoring
Ucms28 CVEs
43%
29%
29%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (60.7%)
Unknown0 (0.0%)
Required11 (39.3%)
Privileges Required
Low7 (25.0%)
High2 (7.1%)
None19 (67.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-25483CRITICAL An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server. | Oct 23, 2020 | 9.8 | 33 | NO | NO |
CVE-2022-38297CRITICAL UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning. | Sep 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-35426CRITICAL UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file. | Aug 10, 2022 | 9.8 | 31 | NO | NO |
CVE-2018-17036CRITICAL An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a | Sep 14, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-17035CRITICAL UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. | Sep 14, 2018 | 9.8 | 30 | NO | NO |
CVE-2022-28443CRITICAL UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability. | Apr 21, 2022 | 9.1 | 29 | NO | NO |
CVE-2020-25537CRITICAL File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission. | Nov 30, 2020 | 9.8 | 29 | NO | NO |
CVE-2022-28440HIGH An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file. | Apr 21, 2022 | 8.8 | 28 | NO | NO |
CVE-2018-20599HIGH UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action. | Dec 30, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-17037HIGH user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3. | Sep 14, 2018 | 8.8 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Ucms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6 | 10 | 8.6 | 1.0% | 0 | 0 |
| 1.5.0 | 2 | 7.5 | 1.4% | 0 | 0 |
| 1.4.8 | 2 | 7.5 | 4.8% | 0 | 0 |
| 1.4.7 | 9 | 6.9 | 0.8% | 0 | 0 |
| 1.4.6 | 6 | 7.8 | 1.0% | 0 | 0 |