📦 Pbootcms

by Pbootcms

🔍 What is Pbootcms?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-37497

CRITICAL CVSS 9.8 Feb 3, 2023

CVE-2021-37497 is a critical SQL injection vulnerability in PbootCMS 3.0.5 that allows remote attackers to execute arbitrary SQL commands via crafted GET requests. This affects all organizations runni...

CVE-2022-32417

CRITICAL CVSS 9.8 Jul 14, 2022

PbootCMS v3.1.2 contains a remote code execution vulnerability in the parserIfLabel function that allows attackers to execute arbitrary code on affected systems. This affects all installations running...

CVE-2020-23580

CRITICAL CVSS 9.8 Jul 8, 2021

CVE-2020-23580 is a remote code execution vulnerability in PbootCMS 2.0.8 that allows attackers to execute arbitrary code through the message board functionality. This affects all installations runnin...

CVE-2023-50082

HIGH CVSS 7.5 Jan 4, 2024

CVE-2023-50082 is an incorrect access control vulnerability in Aoyun Technology pbootcms V3.1.2 that allows remote attackers to bypass authentication and access the backend management platform without...

CVE-2021-28245

HIGH CVSS 7.5 Mar 31, 2021

PbootCMS 3.0.4 contains a SQL injection vulnerability in the search parameter of index.php that allows attackers to execute arbitrary SQL commands. This can lead to unauthorized data access, including...

CVE-2025-15154

MEDIUM CVSS 5.3 Dec 28, 2025

This vulnerability in PbootCMS allows attackers to spoof IP addresses by manipulating the X-Forwarded-For header. The system incorrectly trusts this header value for user IP identification, enabling I...

CVE-2020-19248

MEDIUM CVSS 5.1 Feb 21, 2025

This SQL injection vulnerability in PbootCMS 1.4.1 allows attackers to inject malicious SQL code through template parsing. Attackers can contaminate template content via search page URLs, which gets e...

CVE-2024-12793

MEDIUM CVSS 4.3 Dec 19, 2024

This CVE-2024-12793 is a path traversal vulnerability in PbootCMS that allows attackers to access files outside the intended directory by manipulating the 'tag' parameter. It affects PbootCMS versions...

CVE-2025-15153

LOW CVSS 3.7 Dec 28, 2025

This vulnerability in PbootCMS allows attackers to access sensitive files or directories through manipulation of the SQLite database file. It affects PbootCMS installations up to version 3.2.12. The a...