Bigtreecms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 45
    Known Exploited: 0
    3
    Critical Level Threats
    16
    High Level Threats
    24
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2023-44954

    Cross Site Scripting vulnerability in BigTree CMS v.4.5.7 allows a remote attacker to execute arbitrary code via the ID parameter in the Developer Settings functions.

    Last Modified: Nov 21, 2024
    Published: Nov 01, 2023

    CVE-2022-36197

    BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.

    Last Modified: Nov 21, 2024
    Published: Aug 03, 2022

    CVE-2020-18467

    Cross Site Scripting (XSS) vulnerabilty exists in BigTree-CMS 4.4.3 in the tag name field found in the Tags page under the General menu via a crafted website name by doing an authenticated POST HTTP request to admin/tags/create.

    Last Modified: Nov 21, 2024
    Published: Aug 26, 2021

    CVE-2020-26670

    A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands through a crafted request sent to the server via the 'Create a New Setting' function.

    Last Modified: Nov 21, 2024
    Published: Jun 01, 2021

    CVE-2020-26669

    A stored cross-site scripting (XSS) vulnerability was discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary web scripts or HTML via the page content to site/index.php/admin/pages/update.

    Last Modified: Nov 21, 2024
    Published: Jun 01, 2021
    Items Per Page
    Bigtreecms Vulnerabilities & Security CVEs | CVE-DB