Ujcms Vulnerabilities

Comprehensive security vulnerability database for Ujcms products

Last updated: Feb 22, 2026
Total CVEs

2

Critical

0

With Exploits

2

Last 30 Days

0

Severity Distribution

Critical0
0%
High0
0%
Medium2
100%
Low0
0%
DescriptionVendor / ProductExploit Status
CVE-2026-29545.3

This vulnerability allows an attacker to remotely inject malicious code into the UJCMS system by manipulating specific input fields in the import function. It can be exploited without any special access, making it a serious risk for systems running the affected version.

ujcmsujcms
Exploit Available
about 1 month agoFeb 22, 2026
CVE-2026-29535.3

An attacker can exploit a vulnerability in Dromara UJCMS to gain unauthorized access to files on the server by manipulating the deleteDirectory function, potentially allowing them to delete or alter important files. This attack can be carried out remotely, and since the vendor has not responded to the issue, it remains a risk for users of this software.

ujcmsujcms
Exploit Available
about 1 month agoFeb 22, 2026

About Ujcms Security

This page tracks all publicly disclosed security vulnerabilities (CVEs) affecting Ujcms products. Our database is updated in real-time from the National Vulnerability Database (NVD) and enriched with exploit information from GitHub and other security research sources.

Each CVE listing includes CVSS severity scores, exploit availability status, AI-powered vulnerability summaries, and links to official patches and security advisories.