Dromara Ujcms vulnerabilities
5 known vulnerabilities affecting dromara/ujcms.
Total CVEs
5
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-12483P3MEDIUMCVSS 5.9PoCv9.6.0v9.6.1+2 more2024-12-12
CVE-2024-12483 [MEDIUM] CWE-285 CVE-2024-12483: A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects
A vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the component User ID Handler. The manipulation leads to authorization bypass. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficu
nvd
CVE-2026-2954P2CRITICALCVSS 9.8v10.0.22026-02-22
CVE-2026-2954 [CRITICAL] CWE-74 CVE-2026-2954: A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possible to initiate the attack remotely. The exploit has been made public and
nvd
CVE-2026-2953P2CRITICALCVSS 9.1v101.22026-02-22
CVE-2026-2953 [CRITICAL] CWE-22 CVE-2026-2953: A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirecto
A vulnerability has been found in Dromara UJCMS 101.2. This issue affects the function deleteDirectory of the file WebFileTemplateController.delete of the component Template Handler. Such manipulation leads to path traversal. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacte
nvd
CVE-2025-2490P4MEDIUMCVSS 5.4v9.7.52025-03-18
CVE-2025-2490 [MEDIUM] CWE-79 CVE-2025-2490: A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this
A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the component File Upload. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit ha
nvd
CVE-2025-2491P4MEDIUMCVSS 5.4v9.7.52025-03-18
CVE-2025-2491 [MEDIUM] CWE-79 CVE-2025-2491: A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the fu
A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Page. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has
nvd