Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
bagecms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-37122
A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows malicious users to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Settings module.
Bagesoft Bagecms 3.1.0
6.5
CVSSv2
CVE-2019-8421
upload/protected/modules/admini/views/post/index.php in BageCMS up to and including 3.1.4 allows SQL Injection via the title or titleAlias parameter.
Bagesoft Bagecms
9.3
CVSSv2
CVE-2018-19560
BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.
Bagesoft Bagecms 3.1.3
6.8
CVSSv2
CVE-2018-19104
In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges.
Bagesoft Bagecms 3.1.3
6.4
CVSSv2
CVE-2018-18257
An issue exists in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.
Bagesoft Bagecms 3.1.3
7.5
CVSSv2
CVE-2018-18258
An issue exists in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.
Bagesoft Bagecms 3.1.3
6.8
CVSSv2
CVE-2018-14582
index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.
Bagesoft Bagecms 3.1.3
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
encryption
CVE-2024-4331
CVE-2024-26925
arbitrary code
CVE-2006-4304
CVE-2024-25458
CVE-2024-27077
reflected XSS
CVE-2024-4059
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started