BoidCMS records
6 published records for vendor boidcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 16.7%
- Pre-auth RCE
- 2
- With a fix record
- 33.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
58Plan | CVE-2023-38836Weaponized | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type cboidcms · boidcms · CWE-434 | High8.8 | — | 76.0% | Aug 21, 2023 |
28Monitor | CVE-2026-39387Proof of concept | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameterboidcms · boidcms · CWE-98 | High7.2 | — | 0.8% | Apr 14, 2026 |
24Monitor | CVE-2024-32342No exploit | A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML vboidcms · boidcms · CWE-79 | Medium6.1 | — | 0.4% | Apr 17, 2024 |
24Monitor | CVE-2024-32343No exploit | A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML vboidcms · boidcms · CWE-79 | Medium6.1 | — | 0.4% | Apr 17, 2024 |
21Monitor | CVE-2024-53255Proof of concept | Reflected Cross-site Scripting in /admin?page=media via file Parameter in BoidCMSboidcms · boidcms · CWE-79 | Medium5.3 | — | 0.9% | Nov 25, 2024 |
21Monitor | CVE-2023-48824No exploit | BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in aboidcms · boidcms · CWE-79 | Medium5.4 | — | 0.5% | Dec 7, 2023 |
- CVE-2023-3883658Plan
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type c
HighCVSS 8.8WeaponizedEPSS 76%boidcms · boidcmsAug 21, 2023
- CVE-2026-3938728Monitor
BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter
HighCVSS 7.2Proof of conceptEPSS 1%boidcms · boidcmsApr 14, 2026
- CVE-2024-3234224Monitor
A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML v
MediumCVSS 6.1No exploitEPSS 0%boidcms · boidcmsApr 17, 2024
- CVE-2024-3234324Monitor
A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML v
MediumCVSS 6.1No exploitEPSS 0%boidcms · boidcmsApr 17, 2024
- CVE-2024-5325521Monitor
Reflected Cross-site Scripting in /admin?page=media via file Parameter in BoidCMS
MediumCVSS 5.3Proof of conceptEPSS 1%boidcms · boidcmsNov 25, 2024
- CVE-2023-4882421Monitor
BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a
MediumCVSS 5.4No exploitEPSS 0%boidcms · boidcmsDec 7, 2023