- EPSS 0.2%
- Veröffentlicht 16.09.2026 15:00:11
- Zuletzt bearbeitet 16.09.2026 17:53:40
A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserController::del/UserController::mod of the file apps/admin/controller/system/UserController.php of the component User Management. Such ma...
- EPSS 0.31%
- Veröffentlicht 16.09.2026 14:45:08
- Zuletzt bearbeitet 18.09.2026 18:18:07
A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross...
CVE-2026-79387
- EPSS 0.32%
- Veröffentlicht 09.09.2026 00:00:00
- Zuletzt bearbeitet 14.09.2026 15:17:07
SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary user account fields (including passwords and roles) via crafted parameters to the User/mod interface, enabling account takeover.
CVE-2026-67960
- EPSS 0.16%
- Veröffentlicht 17.08.2026 00:00:00
- Zuletzt bearbeitet 31.08.2026 20:12:02
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
CVE-2026-12066
- EPSS 0.29%
- Veröffentlicht 12.06.2026 13:00:07
- Zuletzt bearbeitet 12.06.2026 16:16:27
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler. The manipulation of the argument username/password...
CVE-2026-36239
- EPSS 0.25%
- Veröffentlicht 26.05.2026 00:00:00
- Zuletzt bearbeitet 23.07.2026 11:10:00
PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
CVE-2026-4514
- EPSS 0.2%
- Veröffentlicht 21.03.2026 10:32:09
- Zuletzt bearbeitet 29.04.2026 01:00:01
A flaw has been found in PbootCMS up to 3.2.12. Affected by this issue is some unknown functionality of the file apps/admin/controller/system/UserController.php of the component Backend. Executing a manipulation of the argument Field can lead to impr...
CVE-2026-4510
- EPSS 0.27%
- Veröffentlicht 21.03.2026 07:16:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A weakness has been identified in PbootCMS up to 3.2.12. This impacts the function alert_location of the file apps/home/controller/MemberController.php of the component Parameter Handler. This manipulation of the argument backurl causes cross site sc...
CVE-2026-4509
- EPSS 0.29%
- Veröffentlicht 21.03.2026 06:02:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A security flaw has been discovered in PbootCMS up to 3.2.12. This affects an unknown function of the file core/function/file.php of the component File Upload. The manipulation of the argument black results in incomplete blacklist. The attack may be ...
CVE-2026-4508
- EPSS 0.26%
- Veröffentlicht 20.03.2026 22:32:10
- Zuletzt bearbeitet 29.04.2026 01:00:01
A vulnerability was identified in PbootCMS up to 3.2.12. The impacted element is the function checkUsername of the file apps/home/controller/MemberController.php of the component Member Login. The manipulation of the argument Username leads to sql in...