Bagesoft maintains a focused content-management system product, BageCMS, that despite a narrow footprint sits in a publicly accessible tier and presents a web-application attack surface. Vulnerabilities affecting this vendor skew toward serious outcomes and cluster around input-handling and code-generation weaknesses—including cross-site scripting, SQL injection, path traversal, code injection, and cross-site request forgery—that are endemic to web CMS platforms and directly expose applications to compromise. Current severity and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bagesoft over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18258CRITICAL An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/u | Oct 11, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-19560HIGH BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account. | Nov 26, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-19104HIGH In BageCMS 3.1.3, upload/index.php has a CSRF vulnerability that can be used to upload arbitrary files and get server privileges. | Nov 8, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-14582HIGH index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account. | Jul 24, 2018 | 8.8 | 25 | NO | NO |
CVE-2018-18257HIGH An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or in | Oct 11, 2018 | 7.5 | 24 | NO | NO |
CVE-2019-8421HIGH upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter. | Feb 17, 2019 | 7.2 | 19 | NO | NO |
CVE-2023-37122MEDIUM A stored cross-site scripting (XSS) vulnerability in Bagecms v3.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Custom Setting | Jul 6, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bagesoft.
Media articles that mention a CVE ID that affects a product developed by Bagesoft — matched by CVE ID, not by vendor name.