sanluan
20 exploits
Active since Jun 2022
PublicCMS 5.202406.d - Cross-Site Scripting in Tag Type Handler via Name Argument
PublicCMS 5.202406.d - Cross-Site Scripting in Voting Management
PublicCMS < 4.0.202302.e - Server-Side Request Forgery via /admin/ueditor?action=catchimage
PublicCMS < 4.0.202302.e - Server-Side Request Forgery via Maintenance SysTask Edit
PublicCMS < 4.0.202302.e - Arbitrary File Upload via /admin/cmsWebFile/doUpload
PublicCMS < 4.0.202302.e - Arbitrary File Upload and Remote Code Execution via /admin/cmsTemplate/savePlace
PublicCMS < 4.0.202302.e - Arbitrary File Upload via /admin/cmsTemplate/save
PublicCMS < 4.0.202302.e - Arbitrary File Upload via /admin/cmsWebFile/save
PublicCMS <4.0.202302.e - Code Injection
publiccms <V4.0.202302.e - Any File Upload
PublicCMS < 4.0.202302.e - Remote Code Execution via cmdarray Parameter
PublicCMS < 4.0.202302.e - Arbitrary File Upload via /admin/cmsTemplate/doUpload
PublicCMS 4.0.202302.e - Template Metadata File Upload Code Execution
Sanluan PublicCMS <4.0-6.202506.d - Privilege Escalation
CVSS 4.2
PublicCMS 5.202406.d - Cross-Site Scripting in Voting Management
CVSS 3.5
PublicCMS < 4.0.202011.b - Server-Side Request Forgery via UEditor Catchimage Action
CVSS 9.8
PublicCMS < 4.0.202204.a - Information Disclosure via SysConfigDataDirective
CVSS 5.3
PublicCMS < 4.0.202204.d - Cross-Site Scripting in Tab Handler
CVSS 3.5
Sanluan PublicCMS <5.202506.a - Open Redirect
CVSS 3.5
Sanluan PublicCMS <5.202506.a - Open Redirect
CVSS 3.5