Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bagecms vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2023-37122
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.
Bagesoft Bagecms 3.1.0
7.2
CVSSv3
CVE-2019-8421
upload/protected/modules/admini/views/post/index.php in BageCMS up to and including 3.1.4 allows SQL Injection via the title or titleAlias parameter.
Bagesoft Bagecms
8.8
CVSSv3
CVE-2018-19560
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
Bagesoft Bagecms 3.1.3
8.8
CVSSv3
CVE-2018-19104
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
Bagesoft Bagecms 3.1.3
7.5
CVSSv3
CVE-2018-18257
An issue exists in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
Bagesoft Bagecms 3.1.3
9.8
CVSSv3
CVE-2018-18258
An issue exists in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
Bagesoft Bagecms 3.1.3
8.8
CVSSv3
CVE-2018-14582
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
Bagesoft Bagecms 3.1.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-30924
CVE-2024-3400
overflow
CVE-2024-23528
CVE-2024-21338
CVE-2024-3818
CVE-2024-23535
NULL pointer dereference
elevation of privilege
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started