CVE-2026-78140 MEDIUM

CVE-2026-78140: Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine

Vendor Dromara
Product UJCMS
Weakness CWE-1336
Published August 23, 2026
Last update August 24, 2026

CVSS base score

5.1/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipulation can lead to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been published and may be used.

Key dates

02Disclosure timeline

August 23, 2026 CVE published
August 24, 2026 Record updated

Related vulnerabilities

04Related CVE