Known Vulnerabilities for Baijiacms by Baijiacms Project
Listed below are 10 of the newest known vulnerabilities associated with "Baijiacms" by "Baijiacms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-45942 json | A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. | 8.8 - HIGH | 2022-12-20 | 2023-08-08 |
| CVE-2022-38931 json | A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force... | 8.8 - HIGH | 2022-09-20 | 2022-09-21 |
| CVE-2022-35150 json | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. | 9.8 - CRITICAL | 2022-08-22 | 2022-08-23 |
| CVE-2021-34250 json | ** REJECT ** DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2021-33396. Reason: This record is a duplicate of CVE-2021-33396. No... | Not Provided | 2022-04-11 | 2023-11-07 |
| CVE-2021-33396 json | Cross Site Request Forgery (CSRF) vulnerability in baijiacms 4.1.4, allows attackers to change the password or other informat... | 6.5 - MEDIUM | 2023-02-15 | 2023-02-23 |
| CVE-2020-25873 json | A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 whi... | 6.5 - MEDIUM | 2021-10-29 | 2021-11-03 |
| CVE-2019-7568 json | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter ... | 9.8 - CRITICAL | 2019-02-07 | 2019-02-07 |
| CVE-2018-16725 json | An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, a... | 6.1 - MEDIUM | 2018-09-08 | 2018-10-26 |
| CVE-2018-16724 json | An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request. | 9.8 - CRITICAL | 2018-09-08 | 2018-10-26 |
| CVE-2018-10503 json | An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edit... | 8.8 - HIGH | 2018-04-27 | 2019-12-03 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Baijiacms Project | Baijiacms | 4_1_4_20170105 | |||
| Application | Baijiacms Project | Baijiacms | 4.0 | |||
| Application | Baijiacms Project | Baijiacms | 3.2 | |||
| Application | Baijiacms Project | Baijiacms | 3.1 | |||
| Application | Baijiacms Project | Baijiacms | 3.0 | |||
| Application | Baijiacms Project | Baijiacms | 2.7 | |||
| Application | Baijiacms Project | Baijiacms | 2.6 |