Ulicms is a content management system with a narrow product scope that punches above its typical representation in vulnerability disclosures, suggesting it remains deployed in a material number of web properties despite limited market visibility. The vendor's vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code; the recurring exposure centers on its web-facing CMS platform through weakness classes including cross-site scripting, authorization bypass, missing authorization checks, and unrestricted file uploads that are characteristic of application-layer access and input-handling flaws. Defenders managing Ulicms instances should prioritize updates and restrict administrative access; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ulicms over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53923CRITICAL UliCMS 2023.1 contains a privilege escalation vulnerability that allows unauthenticated attackers to create administrative accounts through the UserController endpoint. Attackers c | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2023-53914CRITICAL UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers c | Dec 17, 2025 | 9.8 | 34 | NO | NO |
CVE-2019-11398MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in UliCMS 2019.2 and 2019.1 allow remote attackers to inject arbitrary web script or HTML via the go parameter to admin/index.ph | May 8, 2019 | 6.1 | 31 | NO | YES |
CVE-2020-12704MEDIUM UliCMS before 2020.2 has PageController stored XSS. | May 7, 2020 | 6.1 | 29 | NO | YES |
CVE-2023-53924HIGH UliCMS 2023.1-sniffing-vicuna contains a remote code execution vulnerability that allows authenticated attackers to upload PHP files with .phar extension during profile avatar uplo | Dec 17, 2025 | 8.8 | 28 | NO | NO |
CVE-2023-53925MEDIUM UliCMS 2023.1 contains a stored cross-site scripting vulnerability that allows attackers to upload malicious SVG files with embedded JavaScript. Attackers can upload crafted SVG fi | Dec 17, 2025 | 6.1 | 21 | NO | NO |
CVE-2020-12703MEDIUM UliCMS before 2020.2 has XSS during PackageController uninstall. | May 7, 2020 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ulicms.
Media articles that mention a CVE ID that affects a product developed by Ulicms — matched by CVE ID, not by vendor name.