pbootcms records
36 published records for vendor pbootcms.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 5.6%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')11
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-668 Exposure of Resource to Wrong Sphere1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
36 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
50Plan | CVE-2022-32417No exploit | PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.pbootcms · pbootcms · CWE-94 | Critical9.8 | — | 35.6% | Jul 14, 2022 |
40Plan | CVE-2018-19595No exploit | PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an pbootcms · pbootcms · CWE-94 | Critical9.8 | — | 3.9% | Nov 27, 2018 |
40Plan | CVE-2020-23580No exploit | Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.pbootcms · pbootcms | Critical9.8 | — | 2.5% | Jul 8, 2021 |
40Plan | CVE-2023-39834No exploit | PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.pbootcms · pbootcms · CWE-77 | Critical9.8 | — | 2.1% | Aug 24, 2023 |
40Plan | CVE-2018-16357No exploit | An issue was discovered in PbootCMS.pbootcms · pbootcms · CWE-89 | Critical9.8 | — | 1.8% | Mar 2, 2020 |
40Plan | CVE-2018-16356No exploit | An issue was discovered in PbootCMS.pbootcms · pbootcms · CWE-89 | Critical9.8 | — | 1.8% | Mar 2, 2020 |
39Monitor | CVE-2018-18450No exploit | apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POSTpbootcms · pbootcms · CWE-89 | Critical9.8 | — | 1.5% | Oct 17, 2018 |
39Monitor | CVE-2018-10133No exploit | PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabpbootcms · pbootcms · CWE-94 | Critical9.8 | — | 1.4% | Apr 16, 2018 |
39Monitor | CVE-2021-37497No exploit | SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.pbootcms · pbootcms · CWE-89 | Critical9.8 | — | 1.2% | Feb 3, 2023 |
39Monitor | CVE-2018-19893No exploit | SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.pbootcms · pbootcms · CWE-89 | Critical9.8 | — | 1.1% | Dec 5, 2018 |
39Monitor | CVE-2018-11369No exploit | An issue was discovered in PbootCMS v1.0.9.pbootcms · pbootcms · CWE-89 | Critical9.8 | — | 1.1% | May 22, 2018 |
35Monitor | CVE-2018-11018No exploit | An issue was discovered in PbootCMS v1.0.7.pbootcms · pbootcms · CWE-352 | High8.8 | — | 0.6% | May 13, 2018 |
35Monitor | CVE-2020-20971No exploit | Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.pbootcms · pbootcms · CWE-352 | High8.8 | — | 0.5% | Jun 2, 2022 |
35Monitor | CVE-2018-10132No exploit | PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontenpbootcms · pbootcms · CWE-352 | High8.8 | — | 0.5% | Apr 16, 2018 |
35Monitor | CVE-2025-46109No exploit | SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET requpbootcms · pbootcms · CWE-89 | High8.8 | — | 0.4% | Jun 18, 2025 |
32Monitor | CVE-2018-18211No exploit | PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.pbootcms · pbootcms · CWE-89 | High8.1 | — | 0.9% | Oct 10, 2018 |
30Monitor | CVE-2021-28245No exploit | PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information throupbootcms · pbootcms · CWE-89 | High7.5 | — | 1.1% | Mar 31, 2021 |
30Monitor | CVE-2023-50082No exploit | Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via sessiopbootcms · pbootcms | High7.5 | — | 0.6% | Jan 4, 2024 |
28Monitor | CVE-2018-19053No exploit | PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statempbootcms · pbootcms · CWE-94 | High7.2 | — | 1.4% | Nov 7, 2018 |
28Monitor | CVE-2019-8422No exploit | A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.phppbootcms · pbootcms · CWE-89 | High7.2 | — | 1.3% | Feb 17, 2019 |
26Monitor | CVE-2020-22535No exploit | Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.pbootcms · pbootcms · CWE-668 | Medium6.5 | — | 0.8% | Jul 9, 2021 |
26Monitor | CVE-2019-7570No exploit | A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.pbootcms · pbootcms · CWE-352 | Medium6.5 | — | 0.5% | Feb 7, 2019 |
26Monitor | CVE-2020-17901No exploit | Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.pbootcms · pbootcms · CWE-352 | Medium6.5 | — | 0.4% | Nov 30, 2020 |
24Monitor | CVE-2024-1018No exploit | PbootCMS cross site scriptingpbootcms · pbootcms · CWE-79 | Medium6.1 | — | 0.5% | Jan 29, 2024 |
24Monitor | CVE-2024-42930No exploit | PbootCMS 3.2.8 is vulnerable to URL Redirect.pbootcms · pbootcms · CWE-601 | Medium6.1 | — | 0.3% | Oct 28, 2024 |
- CVE-2022-3241750Plan
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
CriticalCVSS 9.8No exploitEPSS 36%pbootcms · pbootcmsJul 14, 2022
- CVE-2018-1959540Plan
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an
CriticalCVSS 9.8No exploitEPSS 4%pbootcms · pbootcmsNov 27, 2018
- CVE-2020-2358040Plan
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
CriticalCVSS 9.8No exploitEPSS 2%pbootcms · pbootcmsJul 8, 2021
- CVE-2023-3983440Plan
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
CriticalCVSS 9.8No exploitEPSS 2%pbootcms · pbootcmsAug 24, 2023
- CVE-2018-1635740Plan
An issue was discovered in PbootCMS.
CriticalCVSS 9.8No exploitEPSS 2%pbootcms · pbootcmsMar 2, 2020
- CVE-2018-1635640Plan
An issue was discovered in PbootCMS.
CriticalCVSS 9.8No exploitEPSS 2%pbootcms · pbootcmsMar 2, 2020
- CVE-2018-1845039Monitor
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST
CriticalCVSS 9.8No exploitEPSS 2%pbootcms · pbootcmsOct 17, 2018
- CVE-2018-1013339Monitor
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLab
CriticalCVSS 9.8No exploitEPSS 1%pbootcms · pbootcmsApr 16, 2018
- CVE-2021-3749739Monitor
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
CriticalCVSS 9.8No exploitEPSS 1%pbootcms · pbootcmsFeb 3, 2023
- CVE-2018-1989339Monitor
SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
CriticalCVSS 9.8No exploitEPSS 1%pbootcms · pbootcmsDec 5, 2018
- CVE-2018-1136939Monitor
An issue was discovered in PbootCMS v1.0.9.
CriticalCVSS 9.8No exploitEPSS 1%pbootcms · pbootcmsMay 22, 2018
- CVE-2018-1101835Monitor
An issue was discovered in PbootCMS v1.0.7.
HighCVSS 8.8No exploitEPSS 1%pbootcms · pbootcmsMay 13, 2018
- CVE-2020-2097135Monitor
Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.
HighCVSS 8.8No exploitEPSS 1%pbootcms · pbootcmsJun 2, 2022
- CVE-2018-1013235Monitor
PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the reconten
HighCVSS 8.8No exploitEPSS 1%pbootcms · pbootcmsApr 16, 2018
- CVE-2025-4610935Monitor
SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET requ
HighCVSS 8.8No exploitEPSS 0%pbootcms · pbootcmsJun 18, 2025
- CVE-2018-1821132Monitor
PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.
HighCVSS 8.1No exploitEPSS 1%pbootcms · pbootcmsOct 10, 2018
- CVE-2021-2824530Monitor
PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information throu
HighCVSS 7.5No exploitEPSS 1%pbootcms · pbootcmsMar 31, 2021
- CVE-2023-5008230Monitor
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via sessio
HighCVSS 7.5No exploitEPSS 1%pbootcms · pbootcmsJan 4, 2024
- CVE-2018-1905328Monitor
PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statem
HighCVSS 7.2No exploitEPSS 1%pbootcms · pbootcmsNov 7, 2018
- CVE-2019-842228Monitor
A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php
HighCVSS 7.2No exploitEPSS 1%pbootcms · pbootcmsFeb 17, 2019
- CVE-2020-2253526Monitor
Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.
MediumCVSS 6.5No exploitEPSS 1%pbootcms · pbootcmsJul 9, 2021
- CVE-2019-757026Monitor
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.
MediumCVSS 6.5No exploitEPSS 1%pbootcms · pbootcmsFeb 7, 2019
- CVE-2020-1790126Monitor
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
MediumCVSS 6.5No exploitEPSS 0%pbootcms · pbootcmsNov 30, 2020
- CVE-2024-101824Monitor
PbootCMS cross site scripting
MediumCVSS 6.1No exploitEPSS 1%pbootcms · pbootcmsJan 29, 2024
- CVE-2024-4293024Monitor
PbootCMS 3.2.8 is vulnerable to URL Redirect.
MediumCVSS 6.1No exploitEPSS 0%pbootcms · pbootcmsOct 28, 2024