Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Pbootcms
(Pbootcms)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 29 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2020-11-30 | CVE-2020-17901 | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user. | Pbootcms | 6.5 | ||
2021-03-31 | CVE-2021-28245 | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information through adding an admin account. | Pbootcms | 7.5 | ||
2021-06-03 | CVE-2020-21003 | Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php. | Pbootcms | 4.8 | ||
2021-07-08 | CVE-2020-20363 | Crossi Site Scripting (XSS) vulnerability in PbootCMS 2.0.3 in admin.php. | Pbootcms | 4.8 | ||
2021-07-08 | CVE-2020-23580 | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. | Pbootcms | 9.8 | ||
2021-07-09 | CVE-2020-22535 | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php. | Pbootcms | 6.5 | ||
2021-08-12 | CVE-2020-18456 | Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php. | Pbootcms | 4.8 | ||
2022-06-02 | CVE-2020-20971 | Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index. | Pbootcms | 8.8 | ||
2022-07-14 | CVE-2022-32417 | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. | Pbootcms | 9.8 | ||
2023-02-03 | CVE-2021-37497 | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. | Pbootcms | 9.8 |