Utcms Project maintains a content management system where the durable vulnerability signal centers on input-handling and request-validation issues, specifically SQL injection, incorrect comparison logic, and server-side request forgery. The exposure pattern reflects typical architectural challenges in web applications that process user input and make outbound requests; live severity, exploitation, and coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Utcms Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-56407HIGH A vulnerability has been found in HuangDou UTCMS V9 and classified as critical. This vulnerability affects the function RunSql of the file app/modules/ut-data/admin/mysql.php. The | Sep 10, 2025 | 8.8 | 27 | NO | NO |
CVE-2025-9402HIGH A vulnerability was found in HuangDou UTCMS 9. This issue affects some unknown processing of the file app/modules/ut-frame/admin/update.php of the component Config Handler. Perform | Aug 25, 2025 | 7.2 | 23 | NO | NO |
A vulnerability has been found in HuangDou UTCMS 9. This vulnerability affects unknown code of the file app/modules/ut-frame/admin/login.php of the component Login. Such manipulati | Aug 25, 2025 | 3.7 | 16 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Utcms Project.
Media articles that mention a CVE ID that affects a product developed by Utcms Project — matched by CVE ID, not by vendor name.