Vulnerabilities (CVE)

Filtered by vendor Baicloud-cms Project Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44302 1 Baicloud-cms Project 1 Baicloud-cms 2024-11-21 6.5 MEDIUM 8.8 HIGH
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.
CVE-2021-41729 1 Baicloud-cms Project 1 Baicloud-cms 2024-11-21 6.4 MEDIUM 9.1 CRITICAL
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.