Server-Side Template Injection in Dromara UJCMS Web-File-Template Endpoint
CVE-2026-78140

5.1MEDIUM

Key Information:

Vendor

Dromara

Status
Vendor
CVE Published:
23 August 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-78140?

A vulnerability exists in Dromara UJCMS versions up to 10.1.3, specifically in the update function of the WebFileTemplateController.java file. The flaw enables a server-side template injection, allowing attackers to manipulate special elements within the template engine. This vulnerability can be exploited remotely, posing a significant threat to the security of applications utilizing this endpoint. Active exploitation has been reported, making it critical for impacted users to address the issue promptly.

Affected Version(s)

UJCMS 10.1.0

UJCMS 10.1.1

UJCMS 10.1.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

dactar (VulDB User)
.