← Vulnerability feed

Vulnerability record · CVE-2021-40881 · published 15 September 2021

CVE-2021-40881: Publiccms vulnerability

Publiccms · Publiccms

An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.

9.8 CVSS 3.1 Critical EPSS 1.6% · top 25.2%
9.8CVSS 3.1 base score, v2 7.5
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue in the BAT file parameters of PublicCMS v4.0 allows attackers to execute arbitrary code.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/sanluan/PublicCMS/issues/57 ExploitIssue TrackingThird Party Advisory
https://github.com/sanluan/PublicCMS/issues/57 ExploitIssue TrackingThird Party Advisory

Track CVE-2021-40881 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-25361Publiccms unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 allows attackers to execute arbi…EPSS 0.71%9.8CVE-2023-46990Publiccms deserialization of untrusted data vulnerabilityDeserialization of Untrusted Data in PublicCMS v.4.0.202302.e allows a remote attacker to execute arbitrary code via a crafted script to the writeRep…EPSS 1.5%9.8CVE-2023-34852Publiccms incorrect permission assignment vulnerabilityPublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.EPSS 1.0%9.8CVE-2020-20914Publiccms sql injection vulnerabilitySQL Injection vulnerability found in San Luan PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via the sql parameter.EPSS 1.1%9.8CVE-2020-20915Publiccms sql injection vulnerabilitySQL Injection vulnerability found in PublicCMS v.4.0 allows a remote attacker to execute arbitrary code via sql parameter of the the SysSiteAdminCont…EPSS 1.1%9.8CVE-2021-27693Publiccms server-side request forgery (ssrf) vulnerabilityServer-side Request Forgery (SSRF) vulnerability in PublicCMS before 4.0.202011.b via /publiccms/admin/ueditor when the action is catchimage.EPSS 1.1%9.8CVE-2022-23389Publiccms os command injection vulnerabilityPublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.EPSS 22%9.8CVE-2018-12914Publiccms unrestricted file upload vulnerabilityA remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a direct…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2021-40881), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.