CVE-2018-17036: Ucms Project Ucms

Critical severity, CVSS 9.8. EPSS: 1.7% chance of exploitation in the next 30 days.

An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

Affected products

Published 2018-09-14. Last modified 2026-06-17.