Bigtreecms
Bigtreecms Bigtree CMS: vulnerabilidades y CVE
Bigtreecms Bigtree CMS tiene 44 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE44
Últimos 12 meses0
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-44954 | Media (5.4) | 0.61% | — | 1 nov 2023 | Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions. |
| CVE-2022-36197 | Media (5.4) | 0.59% | — | 3 ago 2022 | BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file. |
| CVE-2020-18467 | Media (5.4) | 0.47% | — | 26 ago 2021 | Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to… |
| CVE-2020-26670 | Alta (8.8) | 1.8% | — | 1 jun 2021 | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting'… |
| CVE-2020-26669 | Media (5.4) | 0.60% | — | 1 jun 2021 | A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to… |
| CVE-2020-26668 | Alta (8.8) | 1.4% | — | 1 jun 2021 | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to inject a malicious SQL query to the applications via the 'Create New… |
| CVE-2018-18380 | Media (5.4) | 1.1% | — | 19 oct 2018 | A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one after a user has logged in to the application. The Session Fixation… |
| CVE-2018-18308 | Media (6.1) | 3.6% | — | 16 oct 2018 | In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area). |
| CVE-2018-17341 | Alta (8.1) | 1.9% | — | 23 sept 2018 | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php?bigtree_htaccess_url=admin/images/..\… |
| CVE-2018-17030 | Alta (7.5) | 2.3% | — | 14 sept 2018 | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php. |
| CVE-2018-1000521 | Media (6.1) | 0.86% | — | 26 jun 2018 | BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerability to attack high-privileged(Developer) users.. This attack appear to… |
| CVE-2018-10364 | Media (5.4) | 0.82% | — | 30 abr 2018 | BigTree before 4.2.22 has XSS in the Users management page via the name or company field. |
| CVE-2018-10574 | Crítica (9.8) | 2.2% | — | 30 abr 2018 | site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php does not prevent… |
| CVE-2018-10183 | Media (6.1) | 0.68% | — | 17 abr 2018 | An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUEST_URI'] echo, as demonstrated by the dir parameter in a file=charsets… |
| CVE-2018-6013 | Media (5.4) | 0.84% | — | 23 ene 2018 | Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter. This issue exists in core/admin/ajax/developer/extensions/file-browser.php. |
| CVE-2017-16961 | Media (6.5) | 1.4% | — | 27 nov 2017 | A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data… |
| CVE-2017-11736 | Alta (8.8) | 1.0% | — | 29 jul 2017 | SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via the tags array parameter. |
| CVE-2017-9548 | Media (5.4) | 0.78% | — | 12 jun 2017 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and… |
| CVE-2017-9547 | Media (5.4) | 0.78% | — | 12 jun 2017 | admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the… |
| CVE-2017-9546 | Media (5.7) | 1.1% | — | 12 jun 2017 | admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revision name. |
| CVE-2017-9449 | Alta (8.8) | 1.1% | — | 6 jun 2017 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted… |
| CVE-2017-9448 | Media (5.4) | 0.59% | — | 6 jun 2017 | Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in… |
| CVE-2017-9444 | Alta (8.8) | 0.45% | — | 5 jun 2017 | BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the… |
| CVE-2017-9443 | Alta (8.8) | 1.3% | — | 5 jun 2017 | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in… |
| CVE-2017-9442 | Alta (8.8) | 2.5% | — | 5 jun 2017 | BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as… |
| CVE-2017-9441 | Baja (2.7) | 0.60% | — | 5 jun 2017 | Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1)… |
| CVE-2017-9428 | Alta (7.5) | 2.0% | — | 4 jun 2017 | A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via ..\ sequences in the directory… |
| CVE-2017-9427 | Alta (8.8) | 1.6% | — | 4 jun 2017 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a… |
| CVE-2017-9379 | Alta (8.8) | 0.46% | — | 2 jun 2017 | Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to… |
| CVE-2017-9378 | Media (6.5) | 0.63% | — | 2 jun 2017 | BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such… |