← Vulnerability feed

Vulnerability record · CVE-2026-2954 · published 22 February 2026

CVE-2026-2954: Ujcms injection vulnerability

UUjcms · Ujcms

A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

2.1 CVSS 4.0 Low EPSS 0.66% · top 50.5% CWE-74 · InjectionCWE-707 · CWE-707
2.1CVSS 4.0 base score, v2 6.5
0.66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassName/url results in injection. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://vuldb.com/?ctiid.347320 Permissions RequiredVDB Entry
https://vuldb.com/?id.347320 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.755222 Third Party AdvisoryVDB Entry
https://www.yuque.com/la12138/pa2fpb/gsz2l14wlz8c4nsn?singleDoc Broken Link

Track CVE-2026-2954 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-51350Ujcms authentication bypass by spoofing vulnerabilityA spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-…EPSS 1.3%9.8CVE-2023-34747Ujcms unrestricted file upload vulnerabilityFile upload vulnerability in ujcms 6.0.2 via /api/backend/core/web-file-upload/upload.EPSS 20%9.8CVE-2023-34865Ujcms path traversal vulnerabilityDirectory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.EPSS 1.2%7.5CVE-2023-34878Ujcms observable discrepancy vulnerabilityAn issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-html/downl…EPSS 0.70%6.5CVE-2023-3231Ujcms information exposure vulnerabilityA vulnerability has been found in UJCMS up to 6.0.2 and classified as problematic. This vulnerability affects unknown code of the component ZIP Packa…EPSS 0.82%6.3CVE-2024-12483Ujcms improper authorization vulnerabilityA vulnerability classified as problematic has been found in Dromara UJCMS up to 9.6.3. This affects an unknown part of the file /users/id of the comp…EPSS 3.6%6.1CVE-2023-24369Ujcms cross-site scripting vulnerabilityA cross-site scripting (XSS) vulnerability in UJCMS v4.1.3 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload …EPSS 0.43%5.4CVE-2024-55452Ujcms open redirect vulnerabilityA URL redirection vulnerability exists in UJCMS 9.6.3 due to improper validation of URLs in the upload and rendering of new block / carousel items. T…EPSS 0.27%

Source: NIST National Vulnerability Database (record CVE-2026-2954), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.