Pbootcms
Pbootcms: vulnerabilidades y CVE
Pbootcms tiene 46 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE46
Últimos 12 meses12
Críticas12
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-92383 | Baja (2.1) | 0.24% | — | 16 sept 2026 | A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the… |
| CVE-2026-92381 | Baja (2) | 0.35% | — | 16 sept 2026 | A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of… |
| CVE-2026-79387 | Media (4.3) | 0.29% | — | 9 sept 2026 | SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface,… |
| CVE-2026-67960 | Crítica (9.8) | 0.73% | — | 17 ago 2026 | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components |
| CVE-2026-12066 | Media (5.5) | 0.29% | — | 12 jun 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of… |
| CVE-2026-36239 | Media (4.3) | 0.24% | — | 26 may 2026 | PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality |
| CVE-2026-4514 | Baja (2.1) | 0.35% | — | 21 mar 2026 | A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the… |
| CVE-2026-4510 | Baja (2.1) | 0.45% | — | 21 mar 2026 | A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the… |
| CVE-2026-4509 | Baja (2.1) | 0.38% | — | 21 mar 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in… |
| CVE-2026-4508 | Media (5.5) | 0.41% | — | 20 mar 2026 | A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the… |
| CVE-2025-15154 | Media (5.5) | 0.25% | — | 28 dic 2025 | A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the… |
| CVE-2025-15153 | Baja (2.9) | 0.51% | — | 28 dic 2025 | A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories… |
| CVE-2025-46109 | Alta (8.8) | 0.42% | — | 18 jun 2025 | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request |
| CVE-2025-3787 | Media (5.1) | 0.46% | — | 18 abr 2025 | A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible… |
| CVE-2025-29389 | Media (6.1) | 0.25% | — | 9 abr 2025 | PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2. |
| CVE-2020-19248 | Media (5.1) | 0.26% | — | 21 feb 2025 | SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering… |
| CVE-2024-12793 | Media (5.3) | 0.50% | — | 19 dic 2024 | A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation… |
| CVE-2024-12789 | Media (5.3) | 0.56% | — | 19 dic 2024 | A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to… |
| CVE-2024-42930 | Media (6.1) | 0.26% | — | 28 oct 2024 | PbootCMS 3.2.8 is vulnerable to URL Redirect. |
| CVE-2024-1018 | Media (6.1) | 0.51% | — | 29 ene 2024 | A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site… |
| CVE-2023-50082 | Alta (7.5) | 0.61% | — | 4 ene 2024 | Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform. |
| CVE-2023-39834 | Crítica (9.8) | 2.1% | — | 24 ago 2023 | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function. |
| CVE-2021-37497 | Crítica (9.8) | 1.2% | — | 3 feb 2023 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. |
| CVE-2022-32417 | Crítica (9.8) | 35% | — | 14 jul 2022 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. |
| CVE-2020-20971 | Alta (8.8) | 0.53% | — | 2 jun 2022 | Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index. |
| CVE-2020-18456 | Media (4.8) | 0.53% | — | 12 ago 2021 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. |
| CVE-2020-22535 | Media (6.5) | 0.80% | — | 9 jul 2021 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. |
| CVE-2020-23580 | Crítica (9.8) | 2.5% | — | 8 jul 2021 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. |
| CVE-2020-20363 | Media (4.8) | 0.57% | — | 8 jul 2021 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. |
| CVE-2020-21003 | Media (4.8) | 0.48% | — | 3 jun 2021 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.