Sploitus

CVE-2026-1111

3 known exploits for CVE-2026-1111

A vulnerability has been found in Sanluan PublicCMS up to 5.202506.d. This impacts the function Save of the file com/publiccms/controller/admin/sys/TaskTemplateAdminController.java of the component Task Template Management Handler. Such manipulation of the argument path leads to path traversal. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products
Sanluan Publiccms
Publiccms
≤ 5.202506.d
Fix
Available
CVSS 3.1
7.2 HIGH
EPSS
0.7% (49th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-01-18
CVE-2026-1111 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2026-1111

Proof-of-concept code and exploit modules indexed by Sploitus