Ucms

Vendor:

First CVE: Sep 14, 2018 · Active for 7 years

28
Total CVEs
More Total CVEs than 96% of tracked products
4.7
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ucms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 14, 2018
7 years ago
Most Recent CVE
Sep 17, 2023
1,040 days ago

CVE Severity & Scoring

Ucms28 CVEs
All CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low28 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None17 (60.7%)
Unknown0 (0.0%)
Required11 (39.3%)
Privileges Required
Low7 (25.0%)
High2 (7.1%)
None19 (67.9%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
Oct 23, 20209.833NONO
UCMS v1.6.0 contains an authentication bypass vulnerability which is exploited via cookie poisoning.
Sep 12, 20229.831NONO
UCMS 1.6 is vulnerable to arbitrary file upload via ucms/sadmin/file PHP file.
Aug 10, 20229.831NONO
An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a
Sep 14, 20189.831NONO
UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.
Sep 14, 20189.830NONO
UCMS v1.6 was discovered to contain an arbitrary file deletion vulnerability.
Apr 21, 20229.129NONO
File upload vulnerability exists in UCMS 1.5.0, and the attacker can take advantage of this vulnerability to obtain server management permission.
Nov 30, 20209.829NONO
An arbitrary file upload vulnerability in UCMS v1.6 allows attackers to execute arbitrary code via a crafted PHP file.
Apr 21, 20228.828NONO
UCMS 1.4.7 allows remote attackers to execute arbitrary PHP code by entering this code during an index.php sadmin_fileedit action.
Dec 30, 20188.828NONO
user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.
Sep 14, 20188.828NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Ucms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6108.61.0%00
1.5.027.51.4%00
1.4.827.54.8%00
1.4.796.90.8%00
1.4.667.81.0%00