Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

PublicCMS — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in PublicCMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with PublicCMS, an open-source content management system developed by the vendor PublicCMS. It compiles known weaknesses ranging from cross-site scripting and SQL injection to server-side request forgery and path traversal issues. The dataset covers vulnerability reports published between 2018 and 2024, providing a comprehensive historical view of security incidents affecting this specific software product. By reviewing this aggregated data, users can efficiently track the vendor’s official security advisories and monitor the chronological pattern of disclosed flaws. The page allows for a deep understanding of common weakness classes prevalent in PublicCMS installations, helping administrators identify systemic risks within their deployment environments. Additionally, it serves as a reference for looking up a product’s vulnerability history, enabling security analysts to assess the long-term stability and maintenance quality of the software. This resource is particularly useful for penetration testers and system administrators seeking to prioritize patching efforts based on the frequency and severity of past issues. The information is organized to facilitate quick identification of affected versions and corresponding remediation strategies, ensuring that stakeholders have access to actionable intelligence without sifting through unstructured public forums. Ultimately, this collection supports proactive security management by highlighting trends and recurring error patterns that may indicate deeper architectural problems within the codebase.

Vendor: sanluan

CVE IDTitleCVSSSeverityPublished
CVE-2026-8740 Sanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine CWE-1336 6.3 Medium2026-05-17
CVE-2026-8739 Sanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded key CWE-321 5.3 Medium2026-05-17
CVE-2026-8738 Sanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic error CWE-840 6.5 Medium2026-05-17
CVE-2026-8737 Sanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authentication CWE-306 5.3 Medium2026-05-17
CVE-2026-6797 Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption CWE-400 4.3 Medium2026-04-21
CVE-2026-6796 Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file CWE-313 4.3 Medium2026-04-21
CVE-2026-5987 Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine CWE-1336 4.7 Medium2026-04-09
CVE-2026-3289 Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversal CWE-22 6.3 Medium2026-02-27
CVE-2026-2010 Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization CWE-285 4.2 Medium2026-02-06
CVE-2026-1112 Sanluan PublicCMS Trade Address Deletion Endpoint TradeAddressController.java delete improper authorization CWE-285 5.4 Medium2026-01-18
CVE-2026-1111 Sanluan PublicCMS Task Template Management TaskTemplateAdminController.java save path traversal CWE-22 4.7 Medium2026-01-18
CVE-2025-7953 Sanluan PublicCMS viewer.html redirect CWE-601 3.5 Low2025-07-22
CVE-2025-7949 Sanluan PublicCMS preview.html redirect CWE-601 3.5 Low2025-07-22
CVE-2024-11070 Sanluan PublicCMS Tag Type save cross site scripting CWE-79 3.5 Low2024-11-11
CVE-2022-3950 sanluan PublicCMS Tab dwz.min.js initLink cross site scripting CWE-707 3.5 Low2022-11-11

All 15 known CVE vulnerabilities affecting PublicCMS with full Chinese analysis, references, and POCs where available.