CVE-2026-78140: Dromara UJCMS web-file-template Endpoint WebFileTemplateController.java update special elements in template engine
Published Aug 23, 2026
·Updated
A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component web-file-template Endpoint. Executing a manipulation can lead to improper neutralization of special elements used in a template engine. The attack can be launched remotely. The exploit has been published and may be used.
Affected Software
1 affected component
Dromara ujcms<=10.1.3
Event History
Aug 23, 2026
CVE Published
via MITRE·07:45 PM
Data Sourced
via MITRE·07:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Apr 16, 58614
Event
via NVD·04:22 AM
Frequently Asked Questions
1
Who can exploit this issue?
The issue is remotely reachable, but exploitation requires high privileges. No user interaction is required.
2
Which versions are affected?
Dromara UJCMS versions up to and including 10.1.3 are reported as affected.
3
Is exploit activity a practical concern?
Yes. A public exploit has been published, so organizations should assume the flaw may be usable by attackers who have the required privileges.