Vulnerabilities (CVE)

Filtered by vendor Pbootcms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-18456 1 Pbootcms 1 Pbootcms 2021-08-16 3.5 LOW 4.8 MEDIUM
Cross Site Scripting (XSS) vulnerability exists in PbootCMS v1.3.7 via the title parameter in the mod function in SingleController.php.
CVE-2020-21003 1 Pbootcms 1 Pbootcms 2021-06-10 3.5 LOW 4.8 MEDIUM
Pbootcms v2.0.3 is vulnerable to Cross Site Scripting (XSS) via admin.php.
CVE-2020-17901 1 Pbootcms 1 Pbootcms 2020-12-01 4.3 MEDIUM 6.5 MEDIUM
Cross-site request forgery (CSRF) in PbootCMS 1.3.2 allows attackers to change the password of a user.
CVE-2019-17417 1 Pbootcms 1 Pbootcms 2019-10-11 3.5 LOW 4.8 MEDIUM
PbootCMS 2.0.2 allows XSS via vectors involving the Pboot/admin.php?p=/Single/index/mcode/1 and Pboot/?contact/ URIs.
CVE-2019-7570 1 Pbootcms 1 Pbootcms 2019-02-07 5.8 MEDIUM 6.5 MEDIUM
A CSRF vulnerability was found in PbootCMS v1.3.6 that can delete users via an admin.php/User/del/ucode/ URI.