VYPR

Pmb

by Pmb Services

CVEs (5)

  • CVE-2025-61168CriNov 25, 2025
    risk 0.64cvss 9.8epss 0.00

    An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.

  • CVE-2024-26289CriMay 27, 2024
    risk 0.64cvss 9.8epss 0.01

    Deserialization of Untrusted Data vulnerability in PMB Services PMB allows Remote Code Inclusion.This issue affects PMB: from 7.5.1 before 7.5.6-2, from 7.4.1 before 7.4.9, from 7.3.1 before 7.3.18.

  • CVE-2023-37177CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in PMB Services PMB v.7.4.7 and before allows a remote unauthenticated attacker to execute arbitrary code via the query parameter in the /admin/convert/export_z3950.php endpoint.

  • CVE-2025-61167MedNov 25, 2025
    risk 0.42cvss 6.5epss 0.00

    SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters.

  • CVE-2014-9457Jan 2, 2015
    risk 0.03cvss epss 0.01

    SQL injection vulnerability in classes/mono_display.class.php in PMB 4.1.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the id parameter to catalog.php.