Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-44954 Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Se… Bigtree Cms No fix yet Fix from $1,6002023-11-01 MEDIUM 5.4 CVE-2022-36197 BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PD… Bigtree Cms No fix yet Fix from $1,6002022-08-03 HIGH 8.1 CVE-2018-17341 BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, … Bigtree Cms No fix yet Fix from $1,9502018-09-23 HIGH 7.5 CVE-2018-17030 BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/f… Bigtree Cms No fix yet Fix from $1,9502018-09-14 MEDIUM 6.1 CVE-2018-1000521 BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vulnerabili… Bigtree Cms No fix yet Fix from $1,6002018-06-26 MEDIUM 6.1 CVE-2018-10183 An issue was discovered in BigTree 4.2.22. There is cross-site scripting (XSS) in /core/inc/lib/less.php/test/index.php because of a $_SERVER['REQUES… Bigtree Cms No fix yet Fix from $1,6002018-04-17 MEDIUM 5.4 CVE-2018-6013 Cross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter. This issue e… Bigtree Cms No fix yet Fix from $1,6002018-01-23