VYPR

Pbootcms

by Pbootcmspro

Source repositories

CVEs (46)

  • CVE-2018-19053HigNov 7, 2018
    risk 0.47cvss 7.2epss 0.01

    PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.

  • CVE-2020-22535MedJul 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.

  • CVE-2020-17901MedNov 30, 2020
    risk 0.42cvss 6.5epss 0.00

    Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.

  • CVE-2019-7570MedFeb 7, 2019
    risk 0.42cvss 6.5epss 0.01

    A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.

  • CVE-2024-12789MedDec 19, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely.…

  • CVE-2026-12066HigJun 12, 2026
    risk 0.40cvss 7.3epss 0.00

    A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in…

  • CVE-2026-4508HigMar 20, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be…

  • CVE-2025-29389MedApr 9, 2025
    risk 0.40cvss 6.1epss 0.00

    PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.

  • CVE-2024-42930MedOct 28, 2024
    risk 0.40cvss 6.1epss 0.00

    PbootCMS 3.2.8 is vulnerable to URL Redirect.

  • CVE-2026-4514MedMar 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The…

  • CVE-2026-4509MedMar 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The…

  • CVE-2025-15154MedDec 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The…

  • CVE-2020-19248MedFeb 21, 2025
    risk 0.33cvss 5.1epss 0.00

    SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse…

  • CVE-2020-18456MedAug 12, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.

  • CVE-2020-20363MedJul 8, 2021
    risk 0.31cvss 4.8epss 0.01

    Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.

  • CVE-2020-21003MedJun 3, 2021
    risk 0.31cvss 4.8epss 0.00

    Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.

  • CVE-2019-17417MedOct 10, 2019
    risk 0.31cvss 4.8epss 0.01

    PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.

  • CVE-2026-79387MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.

  • CVE-2026-36239MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

  • CVE-2024-12793MedDec 19, 2024
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to path traversal. The attack may…