Pbootcms / Pbootcms
36 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-92383 | PbootCMS User Management UserController.php mod cross-site request forgery | MEDIUM | 5.3 | Sep 16, 2026 |
| CVE-2026-92381 | PbootCMS Template Rendering ContentController.php decode_string cross site scripting | MEDIUM | 5.1 | Sep 16, 2026 |
| CVE-2026-12066 | PbootCMS Password MemberController.php retrieve password recovery | MEDIUM | 6.9 | Jun 12, 2026 |
| CVE-2026-4514 | PbootCMS Backend UserController.php access control | MEDIUM | 5.3 | Mar 21, 2026 |
| CVE-2026-4510 | PbootCMS Parameter MemberController.php alert_location cross site scripting | MEDIUM | 5.3 | Mar 21, 2026 |
| CVE-2026-4509 | PbootCMS File Upload file.php incomplete blacklist | MEDIUM | 5.3 | Mar 21, 2026 |
| CVE-2026-4508 | PbootCMS Member Login MemberController.php checkUsername sql injection | MEDIUM | 6.9 | Mar 20, 2026 |
| CVE-2025-15154 | PbootCMS Header handle.php get_user_ip less trusted source | MEDIUM | 6.9 | Dec 28, 2025 |
| CVE-2025-15153 | PbootCMS SQLite Database pbootcms.db file access | MEDIUM | 6.3 | Dec 28, 2025 |
| CVE-2025-46109 | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request | HIGH | 8.8 | Jun 18, 2025 |
| CVE-2025-3787 | PbootCMS Image server-side request forgery | MEDIUM | 5.1 | Apr 18, 2025 |
| CVE-2025-29389 | PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2. | MEDIUM | 6.1 | Apr 9, 2025 |
| CVE-2020-19248 | SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by… | MEDIUM | 5.1 | Feb 21, 2025 |
| CVE-2024-12793 | PbootCMS IndexController.php path traversal | MEDIUM | 5.3 | Dec 19, 2024 |
| CVE-2024-12789 | PbootCMS IndexController.php code injection | MEDIUM | 5.3 | Dec 19, 2024 |
| CVE-2024-42930 | PbootCMS 3.2.8 is vulnerable to URL Redirect. | MEDIUM | 6.1 | Oct 28, 2024 |
| CVE-2024-1018 | PbootCMS cross site scripting | MEDIUM | 6.1 | Jan 29, 2024 |
| CVE-2023-50082 | Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a… | HIGH | 7.5 | Jan 4, 2024 |
| CVE-2023-39834 | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function. | CRITICAL | 9.8 | Aug 24, 2023 |
| CVE-2021-37497 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. | CRITICAL | 9.8 | Feb 3, 2023 |
| CVE-2022-32417 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. | CRITICAL | 9.8 | Jul 14, 2022 |
| CVE-2020-20971 | Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index. | HIGH | 8.8 | Jun 1, 2022 |
| CVE-2020-18456 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. | MEDIUM | 4.8 | Aug 12, 2021 |
| CVE-2020-22535 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | MEDIUM | 6.5 | Jul 9, 2021 |
| CVE-2020-23580 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. | CRITICAL | 9.8 | Jul 8, 2021 |
Showing 1 to 25 of 36 CVEs