beescms records
6 published records for vendor beescms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-31011No exploit | Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolatebeescms · beescms · CWE-94 | Critical9.8 | — | 1.2% | Apr 3, 2024 |
36Monitor | CVE-2018-12739Proof of concept | In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.beescms · beescms · CWE-352 | High8.8 | — | 2.4% | Jul 5, 2018 |
35Monitor | CVE-2020-23572No exploit | BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php.beescms · beescms · CWE-434 | High8.8 | — | 1.3% | Nov 8, 2021 |
35Monitor | CVE-2019-8347No exploit | BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=usbeescms · beescms · CWE-352 | High8.8 | — | 0.7% | Feb 15, 2019 |
35Monitor | CVE-2018-10266No exploit | BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.beescms · beescms · CWE-352 | High8.8 | — | 0.6% | Apr 21, 2018 |
26Monitor | CVE-2020-22334No exploit | Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /abeescms · beescms · CWE-352 | Medium6.5 | — | 0.4% | May 8, 2023 |
- CVE-2024-3101139Monitor
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolate
CriticalCVSS 9.8No exploitEPSS 1%beescms · beescmsApr 3, 2024
- CVE-2018-1273936Monitor
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
HighCVSS 8.8Proof of conceptEPSS 2%beescms · beescmsJul 5, 2018
- CVE-2020-2357235Monitor
BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php.
HighCVSS 8.8No exploitEPSS 1%beescms · beescmsNov 8, 2021
- CVE-2019-834735Monitor
BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=us
HighCVSS 8.8No exploitEPSS 1%beescms · beescmsFeb 15, 2019
- CVE-2018-1026635Monitor
BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.
HighCVSS 8.8No exploitEPSS 1%beescms · beescmsApr 21, 2018
- CVE-2020-2233426Monitor
Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /a
MediumCVSS 6.5No exploitEPSS 0%beescms · beescmsMay 8, 2023