publiccms CVE Vulnerabilities & Metrics

Focus on publiccms vulnerabilities and metrics.

Last updated: 16 Apr 2025, 22:25 UTC

About publiccms Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with publiccms. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total publiccms CVEs: 29
Earliest CVE date: 26 May 2018, 21:29 UTC
Latest CVE date: 13 Nov 2024, 16:15 UTC

Latest CVE reference: CVE-2024-11175

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 11

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 175.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 175.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical publiccms CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.01

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 20
4.0-6.9 6
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS publiccms CVEs

These are the five CVEs with the highest CVSS scores for publiccms, sorted by severity first and recency.

All CVEs for publiccms

CVE-2024-11175 publiccms vulnerability CVSS: 4.0 13 Nov 2024, 16:15 UTC

A vulnerability was found in Public CMS 5.202406.d and classified as problematic. This issue affects some unknown processing of the file /admin/cmsVote/save of the component Voting Management. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named b9530b9cc1f5cfdad4b637874f59029a6283a65c. It is recommended to apply a patch to fix this issue.

CVE-2024-40552 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.

CVE-2024-40551 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-40550 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlaceMetaData of Public CMS v.4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-40549 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/savePlace of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-40548 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

An arbitrary file upload vulnerability in the component /admin/cmsTemplate/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-40547 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

PublicCMS v4.0.202302.e was discovered to contain an arbitrary file content replacement vulnerability via the component /admin/cmsTemplate/replace.

CVE-2024-40546 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-40545 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

An arbitrary file upload vulnerability in the component /admin/cmsWebFile/doUpload of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

CVE-2024-40544 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/#maintenance_sysTask/edit.

CVE-2024-40543 publiccms vulnerability CVSS: 0 12 Jul 2024, 16:15 UTC

PublicCMS v4.0.202302.e was discovered to contain a Server-Side Request Forgery (SSRF) via the component /admin/ueditor?action=catchimage.

CVE-2023-51252 publiccms vulnerability CVSS: 0 10 Jan 2024, 09:15 UTC

PublicCMS 4.0 is vulnerable to Cross Site Scripting (XSS). Because files can be uploaded and online preview function is provided, pdf files and html files containing malicious code are uploaded, an XSS popup window is realized through online viewing.

CVE-2023-46990 publiccms vulnerability CVSS: 0 20 Nov 2023, 20:15 UTC

Deserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeReplace function.

CVE-2023-48204 publiccms vulnerability CVSS: 0 16 Nov 2023, 00:15 UTC

An issue in PublicCMS v.4.0.202302.e allows a remote attacker to obtain sensitive information via the appToken and Parameters parameter of the api/method/getHtml component.

CVE-2023-34852 publiccms vulnerability CVSS: 0 15 Jun 2023, 20:15 UTC

PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.

CVE-2020-20915 publiccms vulnerability CVSS: 0 04 Apr 2023, 15:15 UTC

SQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminControl.

CVE-2020-20914 publiccms vulnerability CVSS: 0 04 Apr 2023, 15:15 UTC

SQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.

CVE-2022-3950 publiccms vulnerability CVSS: 0 11 Nov 2022, 14:15 UTC

A vulnerability, which was classified as problematic, was found in sanluan PublicCMS. Affected is the function initLink of the file dwz.min.js of the component Tab Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The name of the patch is a972dc9b1c94aea2d84478bf26283904c21e4ca2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-213456.

CVE-2021-27693 publiccms vulnerability CVSS: 0 02 Sep 2022, 18:15 UTC

Server-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.

CVE-2022-29784 publiccms vulnerability CVSS: 5.0 03 Jun 2022, 21:15 UTC

PublicCMS V4.0.202204.a and below contains an information leak via the component /views/directive/sys/SysConfigDataDirective.java.

CVE-2022-23389 publiccms vulnerability CVSS: 7.5 14 Feb 2022, 21:15 UTC

PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.

CVE-2021-40881 publiccms vulnerability CVSS: 7.5 15 Sep 2021, 22:15 UTC

An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.

CVE-2020-21333 publiccms vulnerability CVSS: 3.5 09 Jul 2021, 17:15 UTC

Cross Site Scripting (XSS) vulnerability in PublicCMS 4.0 to get an admin cookie when the Administrator reviews submit case.

CVE-2018-18927 publiccms vulnerability CVSS: 3.5 04 Nov 2018, 05:29 UTC

An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.

CVE-2018-17368 publiccms vulnerability CVSS: 5.0 23 Sep 2018, 22:29 UTC

An issue was discovered in PublicCMS V4.0.180825. For an invalid login attempt, the response length is different depending on whether the username is valid, which makes it easier to conduct brute-force attacks.

CVE-2018-12914 publiccms vulnerability CVSS: 7.5 27 Jun 2018, 18:29 UTC

A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .jsp URI.

CVE-2018-12494 publiccms vulnerability CVSS: 4.0 15 Jun 2018, 18:29 UTC

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsTemplate/content.html?path=../ URI.

CVE-2018-12493 publiccms vulnerability CVSS: 4.0 15 Jun 2018, 18:29 UTC

An issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an admin/cmsWebFile/list.html?path=../ URI.

CVE-2018-11500 publiccms vulnerability CVSS: 6.8 26 May 2018, 21:29 UTC

An issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in "admin/sysUser/save.do?callbackType=closeCurrent&navTabId=sysUser/list" that can add an admin account.