BoidCMS kayıtları
boidcms üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %16,7
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %33,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
58Planlayın | CVE-2023-38836Silahlaştırılmış | File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type cboidcms · boidcms · CWE-434 | Yüksek8,8 | — | %76,0 | 21 Ağu 2023 |
28İzleyin | CVE-2026-39387Kavram kanıtı | BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameterboidcms · boidcms · CWE-98 | Yüksek7,2 | — | %0,8 | 14 Nis 2026 |
24İzleyin | CVE-2024-32342İstismar yok | A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML vboidcms · boidcms · CWE-79 | Orta6,1 | — | %0,4 | 17 Nis 2024 |
24İzleyin | CVE-2024-32343İstismar yok | A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML vboidcms · boidcms · CWE-79 | Orta6,1 | — | %0,4 | 17 Nis 2024 |
21İzleyin | CVE-2024-53255Kavram kanıtı | Reflected Cross-site Scripting in /admin?page=media via file Parameter in BoidCMSboidcms · boidcms · CWE-79 | Orta5,3 | — | %0,9 | 25 Kas 2024 |
21İzleyin | CVE-2023-48824İstismar yok | BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in aboidcms · boidcms · CWE-79 | Orta5,4 | — | %0,5 | 7 Ara 2023 |
- CVE-2023-3883658Planlayın
File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type c
YüksekCVSS 8,8SilahlaştırılmışEPSS %76boidcms · boidcms21 Ağu 2023
- CVE-2026-3938728İzleyin
BoidCMS: Local File Inclusion (LFI) leads to Remote Code Execution (RCE) via tpl parameter
YüksekCVSS 7,2Kavram kanıtıEPSS %1boidcms · boidcms14 Nis 2026
- CVE-2024-3234224İzleyin
A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML v
OrtaCVSS 6,1İstismar yokEPSS %0boidcms · boidcms17 Nis 2024
- CVE-2024-3234324İzleyin
A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML v
OrtaCVSS 6,1İstismar yokEPSS %0boidcms · boidcms17 Nis 2024
- CVE-2024-5325521İzleyin
Reflected Cross-site Scripting in /admin?page=media via file Parameter in BoidCMS
OrtaCVSS 5,3Kavram kanıtıEPSS %1boidcms · boidcms25 Kas 2024
- CVE-2023-4882421İzleyin
BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a
OrtaCVSS 5,4İstismar yokEPSS %0boidcms · boidcms7 Ara 2023