Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

PublicCMS — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in PublicCMS, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for PublicCMS, a content management system, categorized by specific weakness types and security tags. The collection comprises disclosed security flaws, ranging from injection attacks to memory corruption issues, spanning from the initial release through the latest maintenance advisories. Readers can use this hub to track the vendor's security responses, analyze recurring weakness patterns, and review the complete vulnerability history of the product.

Vendor: sanluan

CVE ID Title CVSS Severity Published
CVE-2026-97721 Sanluan PublicCMS exportExcel/exportData SysUserAdminController.java CmsContentAdminController authorization CWE-639 2.7 Low 2026-09-25
CVE-2026-8740 Sanluan PublicCMS templateResult API TemplateResultDirective.java execute special elements used in a template engine CWE-1336 6.3 Medium 2026-05-17
CVE-2026-8739 Sanluan PublicCMS SafeConfigComponent.java getSignKey hard-coded key CWE-321 5.3 Medium 2026-05-17
CVE-2026-8738 Sanluan PublicCMS Trade Payment Flow TradeOrderController.java AccountGatewayComponent.pay logic error CWE-840 6.5 Medium 2026-05-17
CVE-2026-8737 Sanluan PublicCMS Trade Address Query TradeAddressListDirective.java execute missing authentication CWE-306 5.3 Medium 2026-05-17
CVE-2026-6797 Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption CWE-400 4.3 Medium 2026-04-21
CVE-2026-6796 Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in file CWE-313 4.3 Medium 2026-04-21
CVE-2026-5987 Sanluan PublicCMS FreeMarker Template AbstractFreemarkerView.java AbstractFreemarkerView.doRender special elements used in a template engine CWE-1336 4.7 Medium 2026-04-09
CVE-2026-3289 Sanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversal CWE-22 6.3 Medium 2026-02-27
CVE-2026-2010 Sanluan PublicCMS Trade Payment TradePaymentService.java paid improper authorization CWE-285 4.2 Medium 2026-02-06
CVE-2026-1112 Sanluan PublicCMS Trade Address Deletion Endpoint TradeAddressController.java delete improper authorization CWE-285 5.4 Medium 2026-01-18
CVE-2026-1111 Sanluan PublicCMS Task Template Management TaskTemplateAdminController.java save path traversal CWE-22 4.7 Medium 2026-01-18
CVE-2025-7953 Sanluan PublicCMS viewer.html redirect CWE-601 3.5 Low 2025-07-22
CVE-2025-7949 Sanluan PublicCMS preview.html redirect CWE-601 3.5 Low 2025-07-22
CVE-2024-11070 Sanluan PublicCMS Tag Type save cross site scripting CWE-79 3.5 Low 2024-11-11
CVE-2022-3950 sanluan PublicCMS Tab dwz.min.js initLink cross site scripting CWE-707 3.5 Low 2022-11-11

All 16 known CVE vulnerabilities affecting PublicCMS with full Chinese analysis, references, and POCs where available.