bagesoft records
7 published records for vendor bagesoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2018-18258No exploit | An issue was discovered in BageCMS 3.1.3.bagesoft · bagecms · CWE-94 | Critical9.8 | — | 1.5% | Oct 11, 2018 |
35Monitor | CVE-2018-19560No exploit | BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.bagesoft · bagecms · CWE-352 | High8.8 | — | 0.7% | Nov 26, 2018 |
35Monitor | CVE-2018-19104No exploit | In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.bagesoft · bagecms · CWE-352 | High8.8 | — | 0.6% | Nov 8, 2018 |
35Monitor | CVE-2018-14582No exploit | index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.bagesoft · bagecms · CWE-352 | High8.8 | — | 0.5% | Jul 24, 2018 |
30Monitor | CVE-2018-18257No exploit | An issue was discovered in BageCMS 3.1.3.bagesoft · bagecms · CWE-22 | High7.5 | — | 1.6% | Oct 11, 2018 |
28Monitor | CVE-2019-8421No exploit | upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.bagesoft · bagecms · CWE-89 | High7.2 | — | 1.2% | Feb 17, 2019 |
21Monitor | CVE-2023-37122No exploit | A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted bagesoft · bagecms · CWE-79 | Medium5.4 | — | 0.3% | Jul 6, 2023 |
- CVE-2018-1825839Monitor
An issue was discovered in BageCMS 3.1.3.
CriticalCVSS 9.8No exploitEPSS 1%bagesoft · bagecmsOct 11, 2018
- CVE-2018-1956035Monitor
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
HighCVSS 8.8No exploitEPSS 1%bagesoft · bagecmsNov 26, 2018
- CVE-2018-1910435Monitor
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
HighCVSS 8.8No exploitEPSS 1%bagesoft · bagecmsNov 8, 2018
- CVE-2018-1458235Monitor
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
HighCVSS 8.8No exploitEPSS 1%bagesoft · bagecmsJul 24, 2018
- CVE-2018-1825730Monitor
An issue was discovered in BageCMS 3.1.3.
HighCVSS 7.5No exploitEPSS 2%bagesoft · bagecmsOct 11, 2018
- CVE-2019-842128Monitor
upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.
HighCVSS 7.2No exploitEPSS 1%bagesoft · bagecmsFeb 17, 2019
- CVE-2023-3712221Monitor
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted
MediumCVSS 5.4No exploitEPSS 0%bagesoft · bagecmsJul 6, 2023