Dromara · Ujcms · CVE-2026-78140
**Name of the Vulnerable Software and Affected Versions**
Dromara UJCMS versions prior to 10.1.4
**Description**
A remote flaw exists in the `web-file-template` endpoint within the `update()` function of the `WebFileTemplateController.java` file. This issue occurs due to the improper neutralization of special elements used in a template engine, which can be triggered through remote manipulation.
**Recommendations**
Update Dromara UJCMS to version 10.1.4 or later.
As a temporary mitigation, restrict access to the `web-file-template` endpoint.