๐Ÿ” CVE Alert

CVE-2026-78140

MEDIUM 4.7

Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine

CVSS Score
4.7
EPSS Score
0.2%
EPSS Percentile
15th

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipulation can lead to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been published and may be used.

CWE CWE-1336 CWE-791
Vendor dromara
Product ujcms
Published Aug 23, 2026
Last Updated Aug 24, 2026
Stay Ahead of the Next One

Get instant alerts for dromara ujcms

Be the first to know when new medium vulnerabilities affecting dromara ujcms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Dromara / UJCMS
10.1.0 10.1.1 10.1.2 10.1.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/394523 vuldb.com: https://vuldb.com/vuln/394523/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78140 vuldb.com: https://vuldb.com/submit/882065 github.com: https://github.com/d0ctorsec/CVE-Reports/blob/main/CVE-UJCMS-v10.1.3-FreeMarker-SSTI/CVE-UJCMS-v10.1.3-FreeMarker-SSTI.md

Credits

๐Ÿ” dactar (VulDB User)