Ofcms Ofcmsproject Ofcms

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Ofcmsproject Ofcms.

By the Year

In 2026 there have been 0 vulnerabilities in Ofcmsproject Ofcms. Last year, in 2025 Ofcms had 1 security vulnerability published. Right now, Ofcms is on track to have less security vulnerabilities in 2026 than it did last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 1 4.30
2024 5 5.40
2023 1 8.80
2022 3 5.63
2021 0 0.00
2020 0 0.00
2019 10 0.00

It may take a day or so for new Ofcms vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Ofcmsproject Ofcms Security Vulnerabilities

OFCMS 1.1.3 XSRF Vulnerability in Unknown Function
CVE-2025-1557 4.3 - Medium - February 22, 2025

A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Session Riding

RCE via TemplateController.save in ofcms 1.1.2
CVE-2024-48235 - October 25, 2024

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.

RCE in ofcms 1.1.2 via FileOutputStream in FileUtils
CVE-2024-48236 - October 25, 2024

An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file

OFCMS 1.1.2 XSS via dict_value in /admin/system/dict/add.json
CVE-2024-9411 - October 01, 2024

A vulnerability classified as problematic has been found in OFCMS 1.1.2. This affects the function add of the file /admin/system/dict/add.json?sqlid=system.dict.save. The manipulation of the argument dict_value leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

XSS

OFCMS V1.1.2 SQL Injection via Table Function
CVE-2024-34256 - May 14, 2024

OFCMS V1.1.2 is vulnerable to SQL Injection via the new table function.

XSS in OFCMS 1.14 Title Add Component via Crafted Payload
CVE-2023-51807 5.4 - Medium - January 16, 2024

Cross Site Scripting vulnerability in OFCMS v.1.14 allows a remote attacker to obtain sensitive information via a crafted payload to the title addition component.

XSS

Privilege Escalation via respwd in Ofcms 1.1.4 PHP CMS
CVE-2023-24760 8.8 - High - March 16, 2023

An issue found in Ofcms v.1.1.4 allows a remote attacker to to escalate privileges via the respwd method in SysUserController.

Improper Privilege Management

OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability
CVE-2022-29653 6.1 - Medium - June 02, 2022

OFCMS v1.1.4 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/comn/service/update.json.

XSS

A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4
CVE-2022-27961 5.4 - Medium - April 10, 2022

A cross-site scripting (XSS) vulnerability at /ofcms/company-c-47 in OFCMS v1.1.4 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Comment text box.

XSS

Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4
CVE-2022-27960 5.4 - Medium - April 10, 2022

Insecure permissions configured in the user_id parameter at SysUserController.java of OFCMS v1.1.4 allows attackers to access and arbitrarily modify users' personal information.

Incorrect Default Permissions

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9608 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadImage URI.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9617 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadFile URI.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9616 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadScrawl URI.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9615 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. It allows admin/system/generate/create?sql= SQL injection, related to SystemGenerateController.java.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9614 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. A command execution vulnerability exists via a template file with '<#assign ex="freemarker.template.utility.Execute"?new()> ${ ex("' followed by the command.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9613 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/ueditor/uploadVideo URI.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9612 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/upload URI.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9611 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. It allows admin/cms/template/getTemplates.html?res_path=res directory traversal, with ../ in the dir parameter, to write arbitrary content (in the file_content parameter) into an arbitrary file (specified by the file_name parameter). This is related to the save function in TemplateController.java.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9610 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. It has admin/cms/template/getTemplates.html?res_path=res&up_dir=../ directory traversal, related to the getTemplates function in TemplateController.java.

An issue was discovered in OFCMS before 1.1.3
CVE-2019-9609 - March 06, 2019

An issue was discovered in OFCMS before 1.1.3. Remote attackers can execute arbitrary code because blocking of .jsp and .jspx files does not consider (for example) file.jsp::$DATA to the admin/comn/service/editUploadImage URI.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Ofcmsproject Ofcms or by Ofcmsproject? Click the Watch button to subscribe.

subscribe