websitebaker records
16 published records for vendor websitebaker.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-306 Missing Authentication for Critical Function1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-7410Proof of concept | Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attackewebsitebaker · websitebaker · CWE-89 | Critical9.8 | — | 2.9% | Apr 3, 2017 |
40Plan | CVE-2020-25990No exploit | WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php.websitebaker · websitebaker · CWE-89 | Critical9.8 | — | 1.7% | Oct 1, 2020 |
39Monitor | CVE-2017-9771No exploit | install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or websitebaker · websitebaker · CWE-94 | Critical9.8 | — | 1.4% | Jun 21, 2017 |
39Monitor | CVE-2017-9360No exploit | WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.websitebaker · websitebaker · CWE-89 | Critical9.8 | — | 1.0% | Jun 2, 2017 |
35Monitor | CVE-2011-2934No exploit | A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate websitebaker · websitebaker · CWE-352 | High8.8 | — | 0.5% | Jan 14, 2020 |
34Monitor | CVE-2021-47788No exploit | WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)websitebaker · websitebaker · CWE-434 | High8.7 | — | 1.0% | Jan 15, 2026 |
31Monitor | CVE-2014-9242Proof of concept | SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via thwebsitebaker · websitebaker · CWE-89 | High7.5 | — | 2.1% | Dec 3, 2014 |
30Monitor | CVE-2011-4322No exploit | websitebaker prior to and including 2.8.1 has an authentication error in backup module.websitebaker · websitebaker · CWE-306 | High7.5 | — | 1.2% | Jan 21, 2020 |
28Monitor | CVE-2011-2933No exploit | An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploawebsitebaker · websitebaker · CWE-434 | High7.2 | — | 1.1% | Jan 14, 2020 |
28Monitor | CVE-2023-53902No exploit | WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpointwebsitebaker · websitebaker · CWE-22 | High7.0 | — | 1.0% | Dec 16, 2025 |
24Monitor | CVE-2017-16514No exploit | Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /websitebaker · websitebaker · CWE-79 | Medium6.1 | — | 0.6% | Jan 10, 2018 |
24Monitor | CVE-2017-9361No exploit | WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.websitebaker · websitebaker · CWE-79 | Medium6.1 | — | 0.6% | Jun 2, 2017 |
20Monitor | CVE-2023-53903No exploit | WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Uploadwebsitebaker · websitebaker · CWE-79 | Medium5.1 | — | 0.2% | Dec 16, 2025 |
20Monitor | CVE-2023-53953No exploit | WebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creationwebsitebaker · websitebaker · CWE-79 | Medium5.1 | — | 0.2% | Dec 19, 2025 |
18Monitor | CVE-2014-9243Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via websitebaker · websitebaker · CWE-79 | Medium4.3 | — | 2.5% | Dec 3, 2014 |
18Monitor | CVE-2015-0553No exploit | Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary webwebsitebaker · websitebaker · CWE-79 | Medium4.3 | — | 2.0% | Jan 21, 2015 |
- CVE-2017-741040Plan
Multiple SQL injection vulnerabilities in account/signup.php and account/signup2.php in WebsiteBaker 2.10.0 and earlier allow remote attacke
CriticalCVSS 9.8Proof of conceptEPSS 3%websitebaker · websitebakerApr 3, 2017
- CVE-2020-2599040Plan
WebsiteBaker 2.12.2 allows SQL Injection via parameter 'display_name' in /websitebaker/admin/preferences/save.php.
CriticalCVSS 9.8No exploitEPSS 2%websitebaker · websitebakerOct 1, 2020
- CVE-2017-977139Monitor
install\save.php in WebsiteBaker v2.10.0 allows remote attackers to execute arbitrary PHP code via the database_username, database_host, or
CriticalCVSS 9.8No exploitEPSS 1%websitebaker · websitebakerJun 21, 2017
- CVE-2017-936039Monitor
WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.
CriticalCVSS 9.8No exploitEPSS 1%websitebaker · websitebakerJun 2, 2017
- CVE-2011-293435Monitor
A Cross Site Request Forgery (CSRF) vulnerability exists in the administrator functions in WebsiteBaker 2.8.1 and earlier due to inadequate
HighCVSS 8.8No exploitEPSS 1%websitebaker · websitebakerJan 14, 2020
- CVE-2021-4778834Monitor
WebsiteBaker 2.13.0 - Remote Code Execution (RCE) (Authenticated)
HighCVSS 8.7No exploitEPSS 1%websitebaker · websitebakerJan 15, 2026
- CVE-2014-924231Monitor
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via th
HighCVSS 7.5Proof of conceptEPSS 2%websitebaker · websitebakerDec 3, 2014
- CVE-2011-432230Monitor
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
HighCVSS 7.5No exploitEPSS 1%websitebaker · websitebakerJan 21, 2020
- CVE-2011-293328Monitor
An Arbitrary File Upload vulnerability exists in admin/media/upload.php in WebsiteBaker 2.8.1 and earlier due to a failure to restrict uploa
HighCVSS 7.2No exploitEPSS 1%websitebaker · websitebakerJan 14, 2020
- CVE-2023-5390228Monitor
WebsiteBaker 2.13.3 Directory Traversal via Media Delete Endpoint
HighCVSS 7.0No exploitEPSS 1%websitebaker · websitebakerDec 16, 2025
- CVE-2017-1651424Monitor
Multiple persistent stored Cross-Site-Scripting (XSS) vulnerabilities in the files /wb/admin/admintools/tool.php (Droplet Description) and /
MediumCVSS 6.1No exploitEPSS 1%websitebaker · websitebakerJan 10, 2018
- CVE-2017-936124Monitor
WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.
MediumCVSS 6.1No exploitEPSS 1%websitebaker · websitebakerJun 2, 2017
- CVE-2023-5390320Monitor
WebsiteBaker 2.13.3 Stored Cross-Site Scripting via SVG File Upload
MediumCVSS 5.1No exploitEPSS 0%websitebaker · websitebakerDec 16, 2025
- CVE-2023-5395320Monitor
WebsiteBaker 2.13.3 Stored Cross-Site Scripting via Page Creation
MediumCVSS 5.1No exploitEPSS 0%websitebaker · websitebakerDec 19, 2025
- CVE-2014-924318Monitor
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via
MediumCVSS 4.3Proof of conceptEPSS 2%websitebaker · websitebakerDec 3, 2014
- CVE-2015-055318Monitor
Cross-site scripting (XSS) vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 SP3 allows remote attackers to inject arbitrary web
MediumCVSS 4.3No exploitEPSS 2%websitebaker · websitebakerJan 21, 2015