Vulnerabilities (CVE)

Filtered by vendor Bosscms Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-22938 1 Bosscms 1 Bosscms 2024-11-21 N/A 7.8 HIGH
Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component.
CVE-2022-44937 1 Bosscms 1 Bosscms 2024-11-21 N/A 6.5 MEDIUM
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
CVE-2022-28606 1 Bosscms 1 Bosscms 2024-11-21 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.