« Volver al listado

Pbootcms

Pbootcms: vulnerabilidades y CVE

Pbootcms tiene 46 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 12 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE46
Últimos 12 meses12
Críticas12
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-92383Baja (2.1)0.24%—16 sept 2026
A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the…
CVE-2026-92381Baja (2)0.35%—16 sept 2026
A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of…
CVE-2026-79387Media (4.3)0.29%—9 sept 2026
SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface,…
CVE-2026-67960Crítica (9.8)0.73%—17 ago 2026
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
CVE-2026-12066Media (5.5)0.29%—12 jun 2026
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of…
CVE-2026-36239Media (4.3)0.24%—26 may 2026
PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
CVE-2026-4514Baja (2.1)0.35%—21 mar 2026
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the…
CVE-2026-4510Baja (2.1)0.45%—21 mar 2026
A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the…
CVE-2026-4509Baja (2.1)0.38%—21 mar 2026
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in…
CVE-2026-4508Media (5.5)0.41%—20 mar 2026
A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the…
CVE-2025-15154Media (5.5)0.25%—28 dic 2025
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the…
CVE-2025-15153Baja (2.9)0.51%—28 dic 2025
A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories…
CVE-2025-46109Alta (8.8)0.42%—18 jun 2025
SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request
CVE-2025-3787Media (5.1)0.46%—18 abr 2025
A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible…
CVE-2025-29389Media (6.1)0.25%—9 abr 2025
PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.
CVE-2020-19248Media (5.1)0.26%—21 feb 2025
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering…
CVE-2024-12793Media (5.3)0.50%—19 dic 2024
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation…
CVE-2024-12789Media (5.3)0.56%—19 dic 2024
A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to…
CVE-2024-42930Media (6.1)0.26%—28 oct 2024
PbootCMS 3.2.8 is vulnerable to URL Redirect.
CVE-2024-1018Media (6.1)0.51%—29 ene 2024
A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site…
CVE-2023-50082Alta (7.5)0.61%—4 ene 2024
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.
CVE-2023-39834Crítica (9.8)2.1%—24 ago 2023
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
CVE-2021-37497Crítica (9.8)1.2%—3 feb 2023
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
CVE-2022-32417Crítica (9.8)35%—14 jul 2022
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
CVE-2020-20971Alta (8.8)0.53%—2 jun 2022
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
CVE-2020-18456Media (4.8)0.53%—12 ago 2021
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
CVE-2020-22535Media (6.5)0.80%—9 jul 2021
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
CVE-2020-23580Crítica (9.8)2.5%—8 jul 2021
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
CVE-2020-20363Media (4.8)0.57%—8 jul 2021
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
CVE-2020-21003Media (4.8)0.48%—3 jun 2021
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1005 Data from Local System1
  2. T1059 Command and Scripting Interpreter1
  3. T1190 Exploit Public-Facing Application1
  4. T1203 Exploitation for Client Execution1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.