Vulnerability index

Browse CVEs

38 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bigtree Cms MEDIUM 5.4
CVE-2023-44954

Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Se…

No fix yet
Fix from $1,600 2023-11-01
Bigtree Cms MEDIUM 5.4
CVE-2022-36197

BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PD…

No fix yet
Fix from $1,600 2022-08-03
Bigtree Cms MEDIUM 5.4
CVE-2020-18467

Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted…

Patch available
Fix from $1,600 2021-08-26
Bigtree Cms HIGH 8.8
CVE-2020-26668

A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to in…

Fix: after 4.4.10
Fix from $1,950 2021-06-01
Bigtree Cms HIGH 8.8
CVE-2020-26670

A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a …

Fix: after 4.4.10
Fix from $1,950 2021-06-01
Bigtree Cms MEDIUM 5.4
CVE-2020-26669

A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute …

Fix: after 4.4.10
Fix from $1,600 2021-06-01
Bigtree Cms MEDIUM 5.4
CVE-2018-18380

A Session Fixation issue was discovered in Bigtree before 4.2.24. admin.php accepts a user-provided PHP session ID instead of regenerating a new one …

Fix: 4.2.24+
Fix from $1,600 2018-10-19
Bigtree Cms MEDIUM 6.1
CVE-2018-18308

In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).

Patch available
Fix from $1,600 2018-10-16
Bigtree Cms HIGH 8.1
CVE-2018-17341

BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, …

No fix yet
Fix from $1,950 2018-09-23
Bigtree Cms HIGH 7.5
CVE-2018-17030

BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/f…

No fix yet
Fix from $1,950 2018-09-14
Bigtree Cms MEDIUM 6.1
CVE-2018-1000521

BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerabili…

No fix yet
Fix from $1,600 2018-06-26
Bigtree Cms MEDIUM 5.4
CVE-2018-10364

BigTree before 4.2.22 has XSS in the Users management page via the name or company field.

Fix: 4.2.22+
Fix from $1,600 2018-04-30
Bigtree Cms CRITICAL 9.8
CVE-2018-10574

site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeSto…

Fix: after 4.2.22
Fix from $2,300 2018-04-30
Bigtree Cms MEDIUM 6.1
CVE-2018-10183

An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUES…

No fix yet
Fix from $1,600 2018-04-17
Bigtree Cms MEDIUM 5.4
CVE-2018-6013

Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter. This issue e…

No fix yet
Fix from $1,600 2018-01-23
Bigtree Cms MEDIUM 6.5
CVE-2017-16961

A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information …

Fix: after 4.2.19
Fix from $1,600 2017-11-27
Bigtree Cms HIGH 8.8
CVE-2017-11736

SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL…

Patch available
Fix from $1,950 2017-07-29
Bigtree Cms MEDIUM 5.7
CVE-2017-9546

admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in…

Fix: after 4.2.18
Fix from $1,600 2017-06-12
Bigtree Cms MEDIUM 5.4
CVE-2017-9547

admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web s…

Fix: after 4.2.18
Fix from $1,600 2017-06-12
Bigtree Cms MEDIUM 5.4
CVE-2017-9548

admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web s…

Fix: after 4.2.18
Fix from $1,600 2017-06-12
Bigtree Cms HIGH 8.8
CVE-2017-9449

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/…

Fix: after 4.2.18
Fix from $1,950 2017-06-06
Bigtree Cms MEDIUM 5.4
CVE-2017-9448

Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via …

Fix: after 4.2.18
Fix from $1,600 2017-06-06
Bigtree Cms HIGH 8.8
CVE-2017-9442

BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, rel…

Fix: after 4.2.18
Fix from $1,950 2017-06-05
Bigtree Cms HIGH 8.8
CVE-2017-9443

BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uplo…

Fix: after 4.2.18
Fix from $1,950 2017-06-05
Bigtree Cms HIGH 8.8
CVE-2017-9444

BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/…

Fix: after 4.2.18
Fix from $1,950 2017-06-05
Bigtree Cms HIGH 8.8
CVE-2017-9427

SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\…

Fix: after 4.2.18
Fix from $1,950 2017-06-04
Bigtree Cms HIGH 7.5
CVE-2017-9428

A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows, allowin…

Fix: after 4.2.18
Fix from $1,950 2017-06-04
Bigtree Cms HIGH 8.8
CVE-2017-9379

Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and th…

Fix: after 4.2.18
Fix from $1,950 2017-06-02
Bigtree Cms MEDIUM 6.5
CVE-2017-9378

BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed …

Fix: after 4.2.18
Fix from $1,600 2017-06-02
Bigtree Cms CRITICAL 9.8
CVE-2017-9364

Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety ch…

Fix: after 4.2.18
Fix from $2,300 2017-06-02