CVE-2025-29389
- EPSS 0.21%
- Veröffentlicht 09.04.2025 15:16:02
- Zuletzt bearbeitet 15.04.2025 13:42:23
PbootCMS v3.2.9 contains a XSS vulnerability in admin.php?p=/Content/index/mcode/2#tab=t2.
CVE-2020-19248
- EPSS 0.25%
- Veröffentlicht 21.02.2025 19:15:10
- Zuletzt bearbeitet 07.04.2025 15:05:33
SQL Injection vulnerability in PbootCMS 1.4.1 in parsing if statements in templates, resulting in a malicious user's ability to contaminate template content by searching for page contamination URLs, thus triggering vulnerabilities when the program us...
CVE-2024-12793
- EPSS 0.48%
- Veröffentlicht 19.12.2024 18:15:09
- Zuletzt bearbeitet 06.01.2025 15:16:15
A vulnerability, which was classified as problematic, has been found in PbootCMS up to 5.2.3. Affected by this issue is some unknown functionality of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to pat...
CVE-2024-12789
- EPSS 0.52%
- Veröffentlicht 19.12.2024 17:15:08
- Zuletzt bearbeitet 10.01.2025 21:42:42
A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipulation of the argument tag leads to code injection. It is possible to ...
CVE-2024-42930
- EPSS 0.25%
- Veröffentlicht 28.10.2024 20:15:05
- Zuletzt bearbeitet 17.04.2025 18:43:12
PbootCMS 3.2.8 is vulnerable to URL Redirect.
CVE-2024-1018
- EPSS 0.51%
- Veröffentlicht 29.01.2024 20:15:15
- Zuletzt bearbeitet 21.11.2024 08:49:36
A vulnerability classified as problematic has been found in PbootCMS 3.2.5-20230421. Affected is an unknown function of the file /admin.php?p=/Area/index#tab=t2. The manipulation of the argument name leads to cross site scripting. It is possible to l...
CVE-2023-50082
- EPSS 0.61%
- Veröffentlicht 04.01.2024 08:15:08
- Zuletzt bearbeitet 09.06.2025 18:15:23
Aoyun Technology pbootcms V3.1.2 is vulnerable to Incorrect Access Control, allows remote attackers to gain sensitive information via session leakage allows a user to avoid logging into the backend management platform.
CVE-2023-39834
- EPSS 1.8%
- Veröffentlicht 24.08.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:15:58
PbootCMS below v3.2.0 was discovered to contain a command injection vulnerability via create_function.
CVE-2021-37497
- EPSS 1.26%
- Veröffentlicht 03.02.2023 18:15:13
- Zuletzt bearbeitet 04.04.2025 21:15:41
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
CVE-2022-32417
- EPSS 32.73%
- Veröffentlicht 14.07.2022 22:15:08
- Zuletzt bearbeitet 21.11.2024 07:06:20
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.