Pbootcms
by Pbootcmspro
Source repositories
CVEs (46)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-19053 | Hig | 0.47 | 7.2 | 0.01 | Nov 7, 2018 | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code. | ||
| CVE-2020-22535 | Med | 0.42 | 6.5 | 0.01 | Jul 9, 2021 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | ||
| CVE-2020-17901 | Med | 0.42 | 6.5 | 0.00 | Nov 30, 2020 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. | ||
| CVE-2019-7570 | Med | 0.42 | 6.5 | 0.01 | Feb 7, 2019 | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI. | ||
| CVE-2024-12789 | Med | 0.41 | 6.3 | 0.01 | Dec 19, 2024 | A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely.… | ||
| CVE-2026-12066 | Hig | 0.40 | 7.3 | 0.00 | Jun 12, 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in… | ||
| CVE-2026-4508 | Hig | 0.40 | 7.3 | 0.00 | Mar 20, 2026 | A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be… | ||
| CVE-2025-29389 | Med | 0.40 | 6.1 | 0.00 | Apr 9, 2025 | PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2. | ||
| CVE-2024-42930 | Med | 0.40 | 6.1 | 0.00 | Oct 28, 2024 | PbootCMS 3.2.8 is vulnerable to URL Redirect. | ||
| CVE-2026-4514 | Med | 0.34 | 6.3 | 0.00 | Mar 21, 2026 | A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The… | ||
| CVE-2026-4509 | Med | 0.34 | 6.3 | 0.00 | Mar 21, 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The… | ||
| CVE-2025-15154 | Med | 0.34 | 5.3 | 0.00 | Dec 28, 2025 | A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The… | ||
| CVE-2020-19248 | Med | 0.33 | 5.1 | 0.00 | Feb 21, 2025 | SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse… | ||
| CVE-2020-18456 | Med | 0.31 | 4.8 | 0.01 | Aug 12, 2021 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. | ||
| CVE-2020-20363 | Med | 0.31 | 4.8 | 0.01 | Jul 8, 2021 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. | ||
| CVE-2020-21003 | Med | 0.31 | 4.8 | 0.00 | Jun 3, 2021 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. | ||
| CVE-2019-17417 | Med | 0.31 | 4.8 | 0.01 | Oct 10, 2019 | PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs. | ||
| CVE-2026-79387 | Med | 0.28 | 4.3 | 0.00 | Sep 9, 2026 | SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover. | ||
| CVE-2026-36239 | Med | 0.28 | 4.3 | 0.00 | May 26, 2026 | PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality | ||
| CVE-2024-12793 | Med | 0.28 | 4.3 | 0.00 | Dec 19, 2024 | A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to path traversal. The attack may… |
- risk 0.47cvss 7.2epss 0.01
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.
- risk 0.42cvss 6.5epss 0.01
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
- risk 0.42cvss 6.5epss 0.00
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
- risk 0.42cvss 6.5epss 0.01
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
- risk 0.41cvss 6.3epss 0.01
A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely.…
- risk 0.40cvss 7.3epss 0.00
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in…
- risk 0.40cvss 7.3epss 0.00
A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be…
- risk 0.40cvss 6.1epss 0.00
PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.
- risk 0.40cvss 6.1epss 0.00
PbootCMS 3.2.8 is vulnerable to URL Redirect.
- risk 0.34cvss 6.3epss 0.00
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The…
- risk 0.34cvss 6.3epss 0.00
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The…
- risk 0.34cvss 5.3epss 0.00
A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The…
- risk 0.33cvss 5.1epss 0.00
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse…
- risk 0.31cvss 4.8epss 0.01
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
- risk 0.31cvss 4.8epss 0.01
Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.
- risk 0.31cvss 4.8epss 0.00
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
- risk 0.31cvss 4.8epss 0.01
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
- risk 0.28cvss 4.3epss 0.00
SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.
- risk 0.28cvss 4.3epss 0.00
PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
- risk 0.28cvss 4.3epss 0.00
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to path traversal. The attack may…
Page 2 of 3