Browse all 4 CVE security advisories affecting ulicms. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Ulicms is a lightweight content management system designed for simple websites and small-scale projects. Historically, it has been susceptible to multiple security vulnerabilities including remote code execution, cross-site scripting, and privilege escalation, as evidenced by its four recorded CVEs. The platform's minimal architecture, while beneficial for performance, has often resulted in insufficient input validation and access control flaws. No major public security incidents have been widely documented, though the consistent pattern of vulnerabilities suggests developers should implement strict security measures when deploying Ulicms in production environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-53925 | UliCMS 2023.1 Stored Cross-Site Scripting via SVG File Upload — UlicmsCWE-79 | 6.1 | Medium | 2025-12-17 |
| CVE-2023-53924 | UliCMS 2023.1-sniffing-vicuna Remote Code Execution via Avatar Upload — UlicmsCWE-434 | 8.8 | High | 2025-12-17 |
| CVE-2023-53923 | UliCMS 2023.1 Privilege Escalation via Unauthenticated Admin Account Creation — UlicmsCWE-862 | 9.8 | Critical | 2025-12-17 |
| CVE-2023-53914 | UliCMS 2023.1 Authentication Bypass via Mass Assignment Vulnerability — UlicmsCWE-639 | 9.8 | Critical | 2025-12-17 |
This page lists every published CVE security advisory associated with ulicms. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.