Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-31613

    BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code."

    Last Modified: Jun 10, 2025
    Published: Jun 10, 2024

    CVE-2024-31609

    Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.

    Last Modified: Apr 18, 2025
    Published: Apr 25, 2024

    CVE-2024-22938

    Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.

    Last Modified: May 29, 2025
    Published: Jan 30, 2024

    CVE-2022-44937

    Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.

    Last Modified: Apr 25, 2025
    Published: Nov 28, 2022

    CVE-2022-28606

    An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.

    Last Modified: Nov 21, 2024
    Published: May 05, 2022
    Items Per Page
    Bosscms Vulnerabilities & Security CVEs | CVE-DB