Bigtreecms maintains a focused content management system product with a modest presence in the self-hosted and small-business web application landscape. The vulnerability profile centers on web-tier flaws characteristic of CMS platforms: cross-site scripting, cross-site request forgery, SQL injection, code injection, and unrestricted file uploads, reflecting the recurring challenges of user input handling and code generation in content management systems. A meaningful share of the vendor's disclosed vulnerabilities reach serious severity, and the exposure shows a moderate tendency toward public exploit availability, indicating the product's attractiveness for toolkit development and automated scanning. Defenders deploying this system should prioritize input validation and file-upload controls in their defensive configuration and remain alert to patching cycles. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bigtreecms over time
Signals from CVEs in this vendor scope (45 CVEs).
45 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-18308MEDIUM In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area). | Oct 16, 2018 | 6.1 | 33 | NO | YES |
CVE-2017-9364CRITICAL Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code. | Jun 2, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-7695CRITICAL Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code. | Apr 11, 2017 | 9.8 | 30 | NO | NO |
CVE-2018-10574CRITICAL site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/ | Apr 30, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-9444HIGH BigTree CMS through 4.2.18 has CSRF related to the core\admin\modules\users\profile\update.php script (modify user information), the index.php/admin/developer/packages/delete/ URI | Jun 5, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-9442HIGH BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP arc | Jun 5, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-9427HIGH SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form | Jun 4, 2017 | 8.8 | 28 | NO | NO |
CVE-2017-7881HIGH BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a | Apr 15, 2017 | 8.8 | 28 | NO | NO |
CVE-2013-4879HIGH SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php. | Aug 14, 2013 | 7.5 | 28 | NO | YES |
CVE-2018-17341HIGH BigTree 4.2.23 on Windows, when Advanced or Simple Rewrite routing is enabled, allows remote attackers to bypass authentication via a ..\ substring, as demonstrated by a launch.php | Sep 23, 2018 | 8.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (45 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bigtreecms.
Media articles that mention a CVE ID that affects a product developed by Bigtreecms — matched by CVE ID, not by vendor name.