Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bigtreecms

First CVE: Aug 14, 2013Active for: 13 yearsTotal CVEs: 45
42.2
VTI Score
High

Bigtreecms maintains a focused content management system product with a modest presence in the self-hosted and small-business web application landscape. The vulnerability profile centers on web-tier flaws characteristic of CMS platforms: cross-site scripting, cross-site request forgery, SQL injection, code injection, and unrestricted file uploads, reflecting the recurring challenges of user input handling and code generation in content management systems. A meaningful share of the vendor's disclosed vulnerabilities reach serious severity, and the exposure shows a moderate tendency toward public exploit availability, indicating the product's attractiveness for toolkit development and automated scanning. Defenders deploying this system should prioritize input validation and file-upload controls in their defensive configuration and remain alert to patching cycles. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
45
Total CVEs
More Total CVEs than 98% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bigtreecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2013
12 years ago
Most Recent CVE
Nov 1, 2023
996 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (45 CVEs).

45 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-18308MEDIUM
In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).
Oct 16, 20186.133NOYES
CVE-2017-9364CRITICAL
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.
Jun 2, 20179.831NONO
CVE-2017-7695CRITICAL
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.
Apr 11, 20179.830NONO
CVE-2018-10574CRITICAL
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/
Apr 30, 20189.828NONO
CVE-2017-9444HIGH
BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI
Jun 5, 20178.828NONO
CVE-2017-9442HIGH
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP arc
Jun 5, 20178.828NONO
CVE-2017-9427HIGH
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form
Jun 4, 20178.828NONO
CVE-2017-7881HIGH
BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a
Apr 15, 20178.828NONO
CVE-2013-4879HIGH
SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php.
Aug 14, 20137.528NOYES
CVE-2018-17341HIGH
BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php
Sep 23, 20188.127NONO
View all 45 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products45 CVEs
56%
36%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network41 (91.1%)
Unknown4 (8.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low39 (86.7%)
High2 (4.4%)
Unknown4 (8.9%)
User Interaction
None16 (35.6%)
Unknown4 (8.9%)
Required25 (55.6%)
Privileges Required
Low22 (48.9%)
High1 (2.2%)
None18 (40.0%)
Unknown4 (8.9%)

Exploit Exposure

Signals from CVEs in this vendor scope (45 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
8.9% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bigtreecms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bigtreecms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bigtreecms's Products

View all 1 CNAs →

Top CWEs