VYPR

Vendor CVEs

Pbootcmspro

All CVEs

46 total · sorted by risk
  • CVE-2022-32417CriJul 14, 2022
    risk 0.66cvss 9.8epss 0.36

    PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

  • CVE-2026-67960CriAug 17, 2026
    risk 0.64cvss 9.8epss 0.01

    An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components

  • CVE-2023-39834CriAug 24, 2023
    risk 0.64cvss 9.8epss 0.02

    PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

  • CVE-2021-37497CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.

  • CVE-2020-23580CriJul 8, 2021
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.

  • CVE-2018-16357CriMar 2, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.

  • CVE-2018-16356CriMar 2, 2020
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.

  • CVE-2018-19893CriDec 6, 2018
    risk 0.64cvss 9.8epss 0.01

    SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.

  • CVE-2018-19595CriNov 27, 2018
    risk 0.64cvss 9.8epss 0.04

    PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl($_GET[a]))}1{/pboot:if}&a=phpinfo(); URI, because of an incorrect…

  • CVE-2018-18450CriOct 17, 2018
    risk 0.64cvss 9.8epss 0.02

    apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.

  • CVE-2018-11369CriMay 22, 2018
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter.

  • CVE-2018-10133CriApr 16, 2018
    risk 0.64cvss 9.8epss 0.01

    PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.

  • CVE-2025-46109HigJun 18, 2025
    risk 0.57cvss 8.8epss 0.00

    SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET request

  • CVE-2020-20971HigJun 2, 2022
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.

  • CVE-2018-11018HigMay 13, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html.

  • CVE-2018-10132HigApr 16, 2018
    risk 0.57cvss 8.8epss 0.01

    PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.

  • CVE-2018-18211HigOct 10, 2018
    risk 0.53cvss 8.1epss 0.01

    PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.

  • CVE-2023-50082HigJan 4, 2024
    risk 0.49cvss 7.5epss 0.01

    Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.

  • CVE-2021-28245HigMar 31, 2021
    risk 0.49cvss 7.5epss 0.01

    PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account.

  • CVE-2019-8422HigFeb 17, 2019
    risk 0.47cvss 7.2epss 0.01

    A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php.

  • CVE-2018-19053HigNov 7, 2018
    risk 0.47cvss 7.2epss 0.01

    PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.

  • CVE-2020-22535MedJul 9, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.

  • CVE-2020-17901MedNov 30, 2020
    risk 0.42cvss 6.5epss 0.00

    Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.

  • CVE-2019-7570MedFeb 7, 2019
    risk 0.42cvss 6.5epss 0.01

    A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.

  • CVE-2024-12789MedDec 19, 2024
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to initiate the attack remotely.…

  • CVE-2026-12066HigJun 12, 2026
    risk 0.40cvss 7.3epss 0.00

    A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password/email/checkcode results in…

  • CVE-2026-4508HigMar 20, 2026
    risk 0.40cvss 7.3epss 0.00

    A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql injection. The attack may be…

  • CVE-2025-29389MedApr 9, 2025
    risk 0.40cvss 6.1epss 0.00

    PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.

  • CVE-2024-42930MedOct 28, 2024
    risk 0.40cvss 6.1epss 0.00

    PbootCMS 3.2.8 is vulnerable to URL Redirect.

  • CVE-2026-4514MedMar 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to improper access controls. The…

  • CVE-2026-4509MedMar 21, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be launched remotely. The…

  • CVE-2025-15154MedDec 28, 2025
    risk 0.34cvss 5.3epss 0.00

    A security vulnerability has been detected in PbootCMS up to 3.2.12. The affected element is the function get_user_ip of the file core/function/handle.php of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to use of less trusted source. The…

  • CVE-2020-19248MedFeb 21, 2025
    risk 0.33cvss 5.1epss 0.00

    SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program uses eval statements to parse…

  • CVE-2020-18456MedAug 12, 2021
    risk 0.31cvss 4.8epss 0.01

    Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.

  • CVE-2020-20363MedJul 8, 2021
    risk 0.31cvss 4.8epss 0.01

    Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php.

  • CVE-2020-21003MedJun 3, 2021
    risk 0.31cvss 4.8epss 0.00

    Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.

  • CVE-2019-17417MedOct 10, 2019
    risk 0.31cvss 4.8epss 0.01

    PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.

  • CVE-2026-79387MedSep 9, 2026
    risk 0.28cvss 4.3epss 0.00

    SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.

  • CVE-2026-36239MedMay 26, 2026
    risk 0.28cvss 4.3epss 0.00

    PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

  • CVE-2024-12793MedDec 19, 2024
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to path traversal. The attack may…

  • CVE-2025-15153LowDec 28, 2025
    risk 0.24cvss 3.7epss 0.01

    A weakness has been identified in PbootCMS up to 3.2.12. Impacted is an unknown function of the file /data/pbootcms.db of the component SQLite Database. Executing a manipulation can lead to files or directories accessible. It is possible to launch the attack remotely. Attacks of…

  • CVE-2026-92383MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such manipulation leads to…

  • CVE-2026-4510MedMar 21, 2026
    risk 0.21cvss 4.3epss 0.00

    A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site scripting. Remote exploitation…

  • CVE-2025-3787LowApr 18, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability was found in PbootCMS 3.2.5. It has been classified as problematic. Affected is an unknown function of the component Image Handler. The manipulation leads to server-side request forgery. It is possible to launch the attack remotely. The exploit has been disclosed…

  • CVE-2026-92381LowSep 16, 2026
    risk 0.16cvss 3.5epss 0.00

    A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross site scripting. The attack…

  • CVE-2024-1018LowJan 29, 2024
    risk 0.16cvss 2.4epss 0.01

    A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site scripting. It is possible to launch the attack remotely.…