bigtreecms records
45 published records for vendor bigtreecms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-352 Cross-Site Request Forgery (CSRF)11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')7
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
45 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-10574No exploit | site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the Bbigtreecms · bigtree cms · CWE-94 | Critical9.8 | — | 2.2% | Apr 30, 2018 |
40Plan | CVE-2017-7695No exploit | Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety chbigtreecms · bigtree cms · CWE-434 | Critical9.8 | — | 2.0% | Apr 11, 2017 |
39Monitor | CVE-2017-9364No exploit | Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a bigtreecms · bigtree cms · CWE-434 | Critical9.8 | — | 1.3% | Jun 2, 2017 |
36Monitor | CVE-2017-9442No exploit | BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web sbigtreecms · bigtree cms · CWE-94 | High8.8 | — | 2.5% | Jun 5, 2017 |
36Monitor | CVE-2020-26670No exploit | A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands tbigtreecms · bigtree cms · CWE-78 | High8.8 | — | 1.8% | Jun 1, 2021 |
35Monitor | CVE-2017-9427No exploit | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\adminbigtreecms · bigtree cms · CWE-89 | High8.8 | — | 1.6% | Jun 4, 2017 |
35Monitor | CVE-2020-26668No exploit | A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attacbigtreecms · bigtree cms · CWE-89 | High8.8 | — | 1.4% | Jun 1, 2021 |
35Monitor | CVE-2017-9443No exploit | BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json ibigtreecms · bigtree cms · CWE-89 | High8.8 | — | 1.3% | Jun 5, 2017 |
35Monitor | CVE-2017-9449No exploit | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/adminbigtreecms · bigtree cms · CWE-89 | High8.8 | — | 1.1% | Jun 6, 2017 |
35Monitor | CVE-2017-11736No exploit | SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbibigtreecms · bigtree cms · CWE-89 | High8.8 | — | 1.0% | Jul 29, 2017 |
35Monitor | CVE-2017-7881No exploit | BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing thbigtreecms · bigtree cms · CWE-352 | High8.8 | — | 0.8% | Apr 15, 2017 |
35Monitor | CVE-2017-9365No exploit | CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fobigtreecms · bigtree cms · CWE-352 | High8.8 | — | 0.5% | Jun 2, 2017 |
35Monitor | CVE-2017-9379No exploit | Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.pbigtreecms · bigtree cms · CWE-352 | High8.8 | — | 0.5% | Jun 2, 2017 |
35Monitor | CVE-2017-9444No exploit | BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.pbigtreecms · bigtree cms · CWE-352 | High8.8 | — | 0.5% | Jun 5, 2017 |
33Monitor | CVE-2018-17341No exploit | BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ subigtreecms · bigtree cms · CWE-287 | High8.1 | — | 1.9% | Sep 23, 2018 |
31Monitor | CVE-2013-4879Proof of concept | SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL bigtreecms · bigtree cms · CWE-89 | High7.5 | — | 2.3% | Aug 14, 2013 |
31Monitor | CVE-2018-17030No exploit | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-bigtreecms · bigtree cms · CWE-94 | High7.5 | — | 2.3% | Sep 13, 2018 |
31Monitor | CVE-2017-9428No exploit | A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windowsbigtreecms · bigtree cms · CWE-22 | High7.5 | — | 2.0% | Jun 4, 2017 |
28Monitor | CVE-2013-4881Proof of concept | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attabigtreecms · bigtree cms · CWE-352 | Medium6.8 | — | 2.2% | Aug 19, 2013 |
28Monitor | CVE-2017-6914No exploit | CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.bigtreecms · bigtree cms · CWE-352 | High7.1 | — | 0.4% | Mar 15, 2017 |
27Monitor | CVE-2013-5313No exploit | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attabigtreecms · bigtree cms · CWE-352 | Medium6.8 | — | 0.9% | Aug 19, 2013 |
26Monitor | CVE-2017-16961No exploit | A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain infbigtreecms · bigtree cms · CWE-89 | Medium6.5 | — | 1.4% | Nov 27, 2017 |
26Monitor | CVE-2017-9378No exploit | BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.bigtreecms · bigtree cms · CWE-863 | Medium6.5 | — | 0.6% | Jun 2, 2017 |
25Monitor | CVE-2018-18308Proof of concept | In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload abigtreecms · bigtree cms · CWE-79 | Medium6.1 | — | 3.6% | Oct 16, 2018 |
24Monitor | CVE-2018-1000521No exploit | BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vubigtreecms · bigtree cms · CWE-79 | Medium6.1 | — | 0.9% | Jun 26, 2018 |
- CVE-2018-1057440Plan
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the B
CriticalCVSS 9.8No exploitEPSS 2%bigtreecms · bigtree cmsApr 30, 2018
- CVE-2017-769540Plan
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety ch
CriticalCVSS 9.8No exploitEPSS 2%bigtreecms · bigtree cmsApr 11, 2017
- CVE-2017-936439Monitor
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a
CriticalCVSS 9.8No exploitEPSS 1%bigtreecms · bigtree cmsJun 2, 2017
- CVE-2017-944236Monitor
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web s
HighCVSS 8.8No exploitEPSS 2%bigtreecms · bigtree cmsJun 5, 2017
- CVE-2020-2667036Monitor
A vulnerability has been discovered in BigTree CMS 4.4.10 and earlier which allows an authenticated attacker to execute arbitrary commands t
HighCVSS 8.8No exploitEPSS 2%bigtreecms · bigtree cmsJun 1, 2021
- CVE-2017-942735Monitor
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin
HighCVSS 8.8No exploitEPSS 2%bigtreecms · bigtree cmsJun 4, 2017
- CVE-2020-2666835Monitor
A SQL injection vulnerability was discovered in /core/feeds/custom.php in BigTree CMS 4.4.10 and earlier which allows an authenticated attac
HighCVSS 8.8No exploitEPSS 1%bigtreecms · bigtree cmsJun 1, 2021
- CVE-2017-944335Monitor
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json i
HighCVSS 8.8No exploitEPSS 1%bigtreecms · bigtree cmsJun 5, 2017
- CVE-2017-944935Monitor
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin
HighCVSS 8.8No exploitEPSS 1%bigtreecms · bigtree cmsJun 6, 2017
- CVE-2017-1173635Monitor
SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbi
HighCVSS 8.8No exploitEPSS 1%bigtreecms · bigtree cmsJul 29, 2017
- CVE-2017-788135Monitor
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing th
HighCVSS 8.8No exploitEPSS 1%bigtreecms · bigtree cmsApr 15, 2017
- CVE-2017-936535Monitor
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?fo
HighCVSS 8.8No exploitEPSS 0%bigtreecms · bigtree cmsJun 2, 2017
- CVE-2017-937935Monitor
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.p
HighCVSS 8.8No exploitEPSS 0%bigtreecms · bigtree cmsJun 2, 2017
- CVE-2017-944435Monitor
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.p
HighCVSS 8.8No exploitEPSS 0%bigtreecms · bigtree cmsJun 5, 2017
- CVE-2018-1734133Monitor
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ su
HighCVSS 8.1No exploitEPSS 2%bigtreecms · bigtree cmsSep 23, 2018
- CVE-2013-487931Monitor
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL
HighCVSS 7.5Proof of conceptEPSS 2%bigtreecms · bigtree cmsAug 14, 2013
- CVE-2018-1703031Monitor
BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-
HighCVSS 7.5No exploitEPSS 2%bigtreecms · bigtree cmsSep 13, 2018
- CVE-2017-942831Monitor
A directory traversal vulnerability exists in core\admin\ajax\developer\extensions\file-browser.php in BigTree CMS through 4.2.18 on Windows
HighCVSS 7.5No exploitEPSS 2%bigtreecms · bigtree cmsJun 4, 2017
- CVE-2013-488128Monitor
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote atta
MediumCVSS 6.8Proof of conceptEPSS 2%bigtreecms · bigtree cmsAug 19, 2013
- CVE-2017-691428Monitor
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page.
HighCVSS 7.1No exploitEPSS 0%bigtreecms · bigtree cmsMar 15, 2017
- CVE-2013-531327Monitor
Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote atta
MediumCVSS 6.8No exploitEPSS 1%bigtreecms · bigtree cmsAug 19, 2013
- CVE-2017-1696126Monitor
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain inf
MediumCVSS 6.5No exploitEPSS 1%bigtreecms · bigtree cmsNov 27, 2017
- CVE-2017-937826Monitor
BigTree CMS through 4.2.18 does not prevent a user from deleting their own account.
MediumCVSS 6.5No exploitEPSS 1%bigtreecms · bigtree cmsJun 2, 2017
- CVE-2018-1830825Monitor
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload a
MediumCVSS 6.1Proof of conceptEPSS 4%bigtreecms · bigtree cmsOct 16, 2018
- CVE-2018-100052124Monitor
BigTree-CMS contains a Cross Site Scripting (XSS) vulnerability in /users/create that can result in The low-privileged users can use this vu
MediumCVSS 6.1No exploitEPSS 1%bigtreecms · bigtree cmsJun 26, 2018