Vulnerabilities (CVE)

Filtered by vendor Baijiacms Project Subscribe
Filtered by product Baijiacms
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-25873 1 Baijiacms Project 1 Baijiacms 2021-11-03 4.0 MEDIUM 6.5 MEDIUM
A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 which allows attackers to arbitrarily delete folders on the server via the "id" parameter.
CVE-2018-16725 1 Baijiacms Project 1 Baijiacms 2018-10-26 4.3 MEDIUM 6.1 MEDIUM
An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component."
CVE-2018-10219 1 Baijiacms Project 1 Baijiacms 2018-05-22 5.0 MEDIUM 5.3 MEDIUM
baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request.