Known Vulnerabilities for products from Baijiacms Project
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Baijiacms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-45942 json | A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4. | 8.8 - HIGH | 2022-12-20 | 2023-08-08 |
| CVE-2022-38931 json | A Server-Side Request Forgery (SSRF) in fetch_net_file_upload function of baijiacmsV4 v4.1.4 allows remote attackers to force... | 8.8 - HIGH | 2022-09-20 | 2022-09-21 |
| CVE-2022-35150 json | Baijicms v4 was discovered to contain an arbitrary file upload vulnerability. | 9.8 - CRITICAL | 2022-08-22 | 2022-08-23 |
| CVE-2021-34250 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | Not Provided | 2022-04-11 | 2023-11-07 |
| CVE-2021-33396 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2023-02-15 | 2023-02-23 |
| CVE-2020-25873 json | A directory traversal vulnerability in the component system/manager/class/web/database.php was discovered in Baijiacms V4 whi... | 6.5 - MEDIUM | 2021-10-29 | 2021-11-03 |
| CVE-2019-7568 json | An issue was discovered in baijiacms V4 that can result in time-based blind SQL injection to get data via the cate parameter ... | 9.8 - CRITICAL | 2019-02-07 | 2019-02-07 |
| CVE-2018-16725 json | An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, a... | 6.1 - MEDIUM | 2018-09-08 | 2018-10-26 |
| CVE-2018-16724 json | An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request. | 9.8 - CRITICAL | 2018-09-08 | 2018-10-26 |
| CVE-2018-10503 json | An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edit... | 8.8 - HIGH | 2018-04-27 | 2019-12-03 |
| CVE-2018-10249 json | baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account. | 8.8 - HIGH | 2018-04-20 | 2018-05-22 |
| CVE-2018-10219 json | baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request. | 5.3 - MEDIUM | 2018-04-19 | 2018-05-22 |
Known software with vulnerabilities from Baijiacms Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Baijiacms Project | Baijiacms | 2.6 |