📦 Pmb

by Sigb

🔍 What is Pmb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-0471

CRITICAL CVSS 9.9 Jan 16, 2025

An unrestricted file upload vulnerability in PMB platform versions 4.0.10 and above allows attackers to upload malicious files and gain remote code execution. This enables complete system compromise i...

CVE-2024-26289

CRITICAL CVSS 9.8 May 27, 2024

CVE-2024-26289 is a critical deserialization vulnerability in PMB Services PMB that allows remote attackers to execute arbitrary code by sending malicious serialized data. This affects PMB installatio...

CVE-2023-37177

CRITICAL CVSS 9.8 Feb 21, 2024

This CVE describes a critical SQL injection vulnerability in PMB Services library management software that allows unauthenticated remote attackers to execute arbitrary SQL commands via the query param...

CVE-2023-24734

CRITICAL CVSS 9.8 Mar 6, 2023

This critical vulnerability in PMB v7.4.6 allows attackers to upload malicious image files through the camera_upload.php component, leading to arbitrary code execution on the server. Any organization ...

CVE-2023-24736

CRITICAL CVSS 9.8 Mar 6, 2023

PMB v7.4.6 contains a remote code execution vulnerability in the /sauvegarde/restaure_act.php component that allows attackers to execute arbitrary code on affected systems. This affects all organizati...

CVE-2023-46474

HIGH CVSS 7.2 Jan 11, 2024

This vulnerability in PMB v7.4.8 allows remote attackers to upload malicious PHP files through the start_import.php endpoint, leading to arbitrary code execution and privilege escalation. Any organiza...

CVE-2025-61167

MEDIUM CVSS 6.5 Nov 25, 2025

SIGB PMB v8.0.1.14 contains SQL injection vulnerabilities in the /opac_css/ajax_selector.php component via the id and datas parameters. This allows attackers to execute arbitrary SQL commands on the d...

CVE-2025-48742

MEDIUM CVSS 5.4 May 27, 2025

This vulnerability in SIGB PMB installer allows remote attackers to execute arbitrary code on affected systems. It affects all systems running PMB versions before 8.0.1.2. The installer component is v...

CVE-2025-48744

MEDIUM CVSS 6.4 May 27, 2025

This vulnerability in SIGB PMB allows attackers to perform Local File Inclusion (LFI) and achieve remote code execution. It affects all installations of SIGB PMB before version 8.0.1.2. Attackers can ...

CVE-2025-0473

MEDIUM CVSS 6.5 Jan 16, 2025

This vulnerability in the PMB platform allows attackers to persist temporary files on the server by intercepting and preventing the cleanup request after file uploads. It affects PMB versions 4.0.10 a...