Bigtreecms / Bigtree Cms
44 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2023-44954 | Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings fun… | MEDIUM | 5.4 | Nov 1, 2023 |
| CVE-2022-36197 | BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file. | MEDIUM | 5.4 | Aug 3, 2022 |
| CVE-2020-18467 | Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website n… | MEDIUM | 5.4 | Aug 26, 2021 |
| CVE-2020-26670 | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted re… | HIGH | 8.8 | Jun 1, 2021 |
| CVE-2020-26669 | A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary… | MEDIUM | 5.4 | Jun 1, 2021 |
| CVE-2020-26668 | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a mal… | HIGH | 8.8 | Jun 1, 2021 |
| CVE-2018-18380 | A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a us… | MEDIUM | 5.4 | Oct 19, 2018 |
| CVE-2018-18308 | In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area). | MEDIUM | 6.1 | Oct 16, 2018 |
| CVE-2018-17341 | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonst… | HIGH | 8.1 | Sep 23, 2018 |
| CVE-2018-17030 | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/proce… | HIGH | 7.5 | Sep 14, 2018 |
| CVE-2018-1000521 | BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerability to atta… | MEDIUM | 6.1 | Jun 26, 2018 |
| CVE-2018-10364 | BigTree before 4.2.22 has XSS in the Users management page via the name or company field. | MEDIUM | 5.4 | Apr 30, 2018 |
| CVE-2018-10574 | site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class… | CRITICAL | 9.8 | Apr 30, 2018 |
| CVE-2018-10183 | An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUEST_URI'] ec… | MEDIUM | 6.1 | Apr 17, 2018 |
| CVE-2018-6013 | Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter. This issue exists in c… | MEDIUM | 5.4 | Jan 23, 2018 |
| CVE-2017-16961 | A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the con… | MEDIUM | 6.5 | Nov 27, 2017 |
| CVE-2017-11736 | SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL commands… | HIGH | 8.8 | Jul 29, 2017 |
| CVE-2017-9548 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or H… | MEDIUM | 5.4 | Jun 12, 2017 |
| CVE-2017-9547 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or H… | MEDIUM | 5.4 | Jun 12, 2017 |
| CVE-2017-9546 | admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revisio… | MEDIUM | 5.7 | Jun 12, 2017 |
| CVE-2017-9449 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/… | HIGH | 8.8 | Jun 6, 2017 |
| CVE-2017-9448 | Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the descri… | MEDIUM | 5.4 | Jun 6, 2017 |
| CVE-2017-9444 | BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/… | HIGH | 8.8 | Jun 5, 2017 |
| CVE-2017-9443 | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded packa… | HIGH | 8.8 | Jun 5, 2017 |
| CVE-2017-9442 | BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to ex… | HIGH | 8.8 | Jun 5, 2017 |
Showing 1 to 25 of 44 CVEs