Baigo develops a focused set of content-management and single-sign-on products that, despite limited breadth, serve as centralized authentication and publishing infrastructure for customer deployments. Vulnerabilities affecting the vendor skew toward serious outcomes with an elevated share reaching critical severity, and recur through web-application weakness classes including code injection, cross-site scripting, cross-site request forgery, and unrestricted file uploads that are characteristic of server-side application logic and input-handling boundaries. Defenders should treat this vendor's updates as a priority for internet-exposed instances; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baigo over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-26607HIGH A remote code execution (RCE) vulnerability in baigo CMS v3.0-alpha-2 was discovered to allow attackers to execute arbitrary code via uploading a crafted PHP file. | Apr 6, 2022 | 7.2 | 27 | NO | NO |
CVE-2019-9227CRITICAL An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be wri | Feb 28, 2019 | 9.8 | 25 | NO | NO |
CVE-2019-10015HIGH baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NA | Mar 24, 2019 | 7.2 | 24 | NO | NO |
CVE-2020-20584MEDIUM A cross site scripting vulnerability in baigo CMS v4.0-beta-1 allows attackers to execute arbitrary web scripts or HTML via the form parameter post to /public/console/profile/info- | Jul 8, 2021 | 6.1 | 23 | NO | NO |
CVE-2019-9226MEDIUM An issue was discovered in baigo CMS 2.1.1. There is a persistent XSS vulnerability that allows remote attackers to inject arbitrary web script or HTML via the opt[base][BG_SITE_NA | Feb 28, 2019 | 6.1 | 22 | NO | NO |
CVE-2018-16458MEDIUM An issue was discovered in baigo CMS v2.1.1. There is an index.php?m=article&c=request CSRF that can cause publication of any article. | Sep 4, 2018 | 6.5 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baigo.
Media articles that mention a CVE ID that affects a product developed by Baigo — matched by CVE ID, not by vendor name.