Skip to content
Noroxi

pbootcms records

36 published records for vendor pbootcms.

All records

36 records
  • PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.

    CriticalCVSS 9.8No exploitEPSS 36%

    pbootcms · pbootcmsJul 14, 2022

  • PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an

    CriticalCVSS 9.8No exploitEPSS 4%

    pbootcms · pbootcmsNov 27, 2018

  • Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.

    CriticalCVSS 9.8No exploitEPSS 2%

    pbootcms · pbootcmsJul 8, 2021

  • PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.

    CriticalCVSS 9.8No exploitEPSS 2%

    pbootcms · pbootcmsAug 24, 2023

  • An issue was discovered in PbootCMS.

    CriticalCVSS 9.8No exploitEPSS 2%

    pbootcms · pbootcmsMar 2, 2020

  • An issue was discovered in PbootCMS.

    CriticalCVSS 9.8No exploitEPSS 2%

    pbootcms · pbootcmsMar 2, 2020

  • apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST

    CriticalCVSS 9.8No exploitEPSS 2%

    pbootcms · pbootcmsOct 17, 2018

  • PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLab

    CriticalCVSS 9.8No exploitEPSS 1%

    pbootcms · pbootcmsApr 16, 2018

  • SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.

    CriticalCVSS 9.8No exploitEPSS 1%

    pbootcms · pbootcmsFeb 3, 2023

  • SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.

    CriticalCVSS 9.8No exploitEPSS 1%

    pbootcms · pbootcmsDec 5, 2018

  • An issue was discovered in PbootCMS v1.0.9.

    CriticalCVSS 9.8No exploitEPSS 1%

    pbootcms · pbootcmsMay 22, 2018

  • An issue was discovered in PbootCMS v1.0.7.

    HighCVSS 8.8No exploitEPSS 1%

    pbootcms · pbootcmsMay 13, 2018

  • Cross Site Request Forgery (CSRF) vulnerability in PbootCMS v2.0.3 via /admin.php?p=/User/index.

    HighCVSS 8.8No exploitEPSS 1%

    pbootcms · pbootcmsJun 2, 2022

  • PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the reconten

    HighCVSS 8.8No exploitEPSS 1%

    pbootcms · pbootcmsApr 16, 2018

  • SQL Injection vulnerability in pbootCMS v.3.2.5 and v.3.2.10 allows a remote attacker to obtain sensitive information via a crafted GET requ

    HighCVSS 8.8No exploitEPSS 0%

    pbootcms · pbootcmsJun 18, 2025

  • PbootCMS 1.2.1 has SQL injection via the HTTP POST data to the api.php/cms/addform?fcode=1 URI.

    HighCVSS 8.1No exploitEPSS 1%

    pbootcms · pbootcmsOct 10, 2018

  • PbootCMS 3.0.4 contains a SQL injection vulnerability through index.php via the search parameter that can reveal sensitive information throu

    HighCVSS 7.5No exploitEPSS 1%

    pbootcms · pbootcmsMar 31, 2021

  • Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via sessio

    HighCVSS 7.5No exploitEPSS 1%

    pbootcms · pbootcmsJan 4, 2024

  • PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statem

    HighCVSS 7.2No exploitEPSS 1%

    pbootcms · pbootcmsNov 7, 2018

  • CVE-2019-8422
    28Monitor

    A SQL Injection vulnerability exists in PbootCMS v1.3.2 via the description parameter in apps\admin\controller\content\ContentController.php

    HighCVSS 7.2No exploitEPSS 1%

    pbootcms · pbootcmsFeb 17, 2019

  • Incorrect Access Control vulnerability in PbootCMS 2.0.6 via the list parameter in the update function in upgradecontroller.php.

    MediumCVSS 6.5No exploitEPSS 1%

    pbootcms · pbootcmsJul 9, 2021

  • CVE-2019-7570
    26Monitor

    A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.

    MediumCVSS 6.5No exploitEPSS 1%

    pbootcms · pbootcmsFeb 7, 2019

  • Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.

    MediumCVSS 6.5No exploitEPSS 0%

    pbootcms · pbootcmsNov 30, 2020

  • CVE-2024-1018
    24Monitor

    PbootCMS cross site scripting

    MediumCVSS 6.1No exploitEPSS 1%

    pbootcms · pbootcmsJan 29, 2024

  • PbootCMS 3.2.8 is vulnerable to URL Redirect.

    MediumCVSS 6.1No exploitEPSS 0%

    pbootcms · pbootcmsOct 28, 2024