Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 23 Aug 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipulation can lead to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been published and may be used. | |
| Title | Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine | |
| First Time appeared |
Ujcms
Ujcms ujcms |
|
| Weaknesses | CWE-1336 CWE-791 |
|
| CPEs | cpe:2.3:a:ujcms:ujcms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Ujcms
Ujcms ujcms |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-23T19:45:07.529Z
Reserved: 2026-08-23T05:44:39.453Z
Link: CVE-2026-78140
No data.
Status : Received
Published: 2026-08-23T20:16:50.380
Modified: 2026-08-23T20:16:50.380
Link: CVE-2026-78140
No data.
OpenCVE Enrichment
No data.