Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2017-16961 |
|
SQL Injection in sqli (CVE-2017-16961)
SQL injection in sqli (CVE-2017-16961). Confidential information can be exposed externally.
|
| CVE-2017-11736 |
|
SQL Injection in sqli (CVE-2017-11736)
SQL injection in sqli (CVE-2017-11736). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9548 |
|
Cross-Site Scripting (XSS) in bigtreecms (CVE-2017-9548)
cross-site scripting in bigtreecms (CVE-2017-9548). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9547 |
|
Cross-Site Scripting (XSS) in bigtreecms (CVE-2017-9547)
cross-site scripting in bigtreecms (CVE-2017-9547). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9546 |
|
Cross-Site Scripting (XSS) in dos (CVE-2017-9546)
cross-site scripting in dos (CVE-2017-9546). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9449 |
|
SQL Injection in sqli (CVE-2017-9449)
SQL injection in sqli (CVE-2017-9449). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9448 |
|
Cross-Site Scripting (XSS) in bigtreecms (CVE-2017-9448)
cross-site scripting in bigtreecms (CVE-2017-9448). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9444 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-9444)
vulnerability in csrf (CVE-2017-9444). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9443 |
|
SQL Injection in sqli (CVE-2017-9443)
SQL injection in sqli (CVE-2017-9443). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9442 |
|
Code Injection in bigtreecms (CVE-2017-9442)
code injection in bigtreecms (CVE-2017-9442). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9441 |
|
Cross-Site Scripting (XSS) in bigtreecms (CVE-2017-9441)
cross-site scripting in bigtreecms (CVE-2017-9441). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-9427 |
|
SQL Injection in sqli (CVE-2017-9427)
SQL injection in sqli (CVE-2017-9427). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9428 |
|
Path Traversal in path-traversal (CVE-2017-9428)
path traversal in path-traversal (CVE-2017-9428). Confidential information can be exposed externally.
|
| CVE-2017-9379 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-9379)
vulnerability in csrf (CVE-2017-9379). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9378 |
|
Authorization Flaw in bigtreecms (CVE-2017-9378)
vulnerability in bigtreecms (CVE-2017-9378). Data can be tampered with by attackers.
|
| CVE-2017-9365 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-9365)
vulnerability in csrf (CVE-2017-9365). Successful exploitation can lead to full system takeover.
|
| CVE-2017-9364 |
|
Unrestricted File Upload in bigtreecms (CVE-2017-9364)
vulnerability in bigtreecms (CVE-2017-9364). Successful exploitation can lead to full system takeover.
|
| CVE-2017-7881 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-7881)
vulnerability in csrf (CVE-2017-7881). Successful exploitation can lead to full system takeover. Exploitable via `Referer header`.
|
| CVE-2017-7695 |
|
Unrestricted File Upload in bigtreecms (CVE-2017-7695)
vulnerability in bigtreecms (CVE-2017-7695). Successful exploitation can lead to full system takeover.
|
| CVE-2017-6918 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-6918)
vulnerability in csrf (CVE-2017-6918). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6917 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-6917)
vulnerability in csrf (CVE-2017-6917). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6916 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-6916)
vulnerability in csrf (CVE-2017-6916). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6915 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-6915)
vulnerability in csrf (CVE-2017-6915). Risk of unauthorized operations or information disclosure.
|
| CVE-2017-6914 |
|
Cross-Site Request Forgery (CSRF) in csrf (CVE-2017-6914)
vulnerability in csrf (CVE-2017-6914). Risk of unauthorized operations or information disclosure.
|
| CVE-2016-10223 |
|
Vulnerability in bigtreecms (CVE-2016-10223)
vulnerability in bigtreecms (CVE-2016-10223). Risk of unauthorized operations or information disclosure.
|