Skip to content
Noroxi

beescms records

6 published records for vendor beescms.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
2
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 19
  3. 21
  4. 23
  5. 24

Bar: total · dark part: CISA KEV.

All records

6 records
  • Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolate

    CriticalCVSS 9.8No exploitEPSS 1%

    beescms · beescmsApr 3, 2024

  • In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.

    HighCVSS 8.8Proof of conceptEPSS 2%

    beescms · beescmsJul 5, 2018

  • BEESCMS v4.0 was discovered to contain an arbitrary file upload vulnerability via the component /admin/upload.php.

    HighCVSS 8.8No exploitEPSS 1%

    beescms · beescmsNov 8, 2021

  • CVE-2019-8347
    35Monitor

    BEESCMS 4.0 has a CSRF vulnerability to add arbitrary VIP accounts via the admin/admin_member.php?action=add&nav=add_web_user&admin_p_nav=us

    HighCVSS 8.8No exploitEPSS 1%

    beescms · beescmsFeb 15, 2019

  • BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.

    HighCVSS 8.8No exploitEPSS 1%

    beescms · beescmsApr 21, 2018

  • Cross Site Request Forgery (CSRF) vulnerability in beescms v4 allows attackers to delete the administrator account via crafted request to /a

    MediumCVSS 6.5No exploitEPSS 0%

    beescms · beescmsMay 8, 2023