VYPR
Vendor

Baijiacms Project

Products
1
CVEs
5
Across products
5
Status
Private

Products

1

Recent CVEs

5
  • CVE-2019-7568CriFeb 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter in an index.php?act=index request.

  • CVE-2022-45942HigDec 20, 2022
    risk 0.59cvss 8.8epss 0.22

    A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

  • CVE-2021-33396MedFeb 15, 2023
    risk 0.42cvss 6.5epss 0.00

    Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other information of an arbitrary account via index.php.

  • CVE-2020-25873MedOct 29, 2021
    risk 0.42cvss 6.5epss 0.01

    A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily delete folders on the server via the "id" parameter.

  • CVE-2018-16725MedSep 8, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component."