Bluecms Project / Bluecms
12 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2025-29150 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request. | MEDIUM | 4.3 | Apr 10, 2025 |
| CVE-2024-45894 | BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request. | MEDIUM | 4.9 | Oct 7, 2024 |
| CVE-2023-33734 | BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php. | CRITICAL | 9.8 | May 30, 2023 |
| CVE-2022-37111 | BlueCMS 1.6 has SQL injection in line 132 of admin/article.php | CRITICAL | 9.8 | Aug 23, 2022 |
| CVE-2022-37112 | BlueCMS 1.6 has SQL injection in line 55 of admin/model.php | CRITICAL | 9.8 | Aug 23, 2022 |
| CVE-2022-37113 | Bluecms 1.6 has SQL injection in line 132 of admin/area.php | CRITICAL | 9.8 | Aug 23, 2022 |
| CVE-2022-27962 | Bluecms 1.6 has a SQL injection vulnerability at cooike. | CRITICAL | 9.8 | May 3, 2022 |
| CVE-2020-19853 | BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php. | CRITICAL | 9.8 | Sep 7, 2021 |
| CVE-2019-10262 | A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in… | CRITICAL | 9.8 | Mar 28, 2019 |
| CVE-2019-9594 | BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | CRITICAL | 9.8 | Mar 6, 2019 |
| CVE-2018-16432 | BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login. | CRITICAL | 9.8 | Sep 4, 2018 |
| CVE-2010-4897 | SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a se… | HIGH | 7.5 | Oct 8, 2011 |
Showing 1 to 12 of 12 CVEs