Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Bigtree Cms MEDIUM 5.4
CVE-2023-44954

Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Se…

No fix yet
Fix from $1,600 2023-11-01
Bigtree Cms MEDIUM 5.4
CVE-2022-36197

BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PD…

No fix yet
Fix from $1,600 2022-08-03
Bigtree Cms HIGH 8.1
CVE-2018-17341

BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, …

No fix yet
Fix from $1,950 2018-09-23
Bigtree Cms HIGH 7.5
CVE-2018-17030

BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/f…

No fix yet
Fix from $1,950 2018-09-14
Bigtree Cms MEDIUM 6.1
CVE-2018-1000521

BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerabili…

No fix yet
Fix from $1,600 2018-06-26
Bigtree Cms MEDIUM 6.1
CVE-2018-10183

An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUES…

No fix yet
Fix from $1,600 2018-04-17
Bigtree Cms MEDIUM 5.4
CVE-2018-6013

Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter. This issue e…

No fix yet
Fix from $1,600 2018-01-23