Bluecms

Vendor:

First CVE: Oct 8, 2011 · Active for 14 years

12
Total CVEs
More Total CVEs than 90% of tracked products
1.5
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
8.7
Avg CVSS
Higher Avg CVSS than 78% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Bluecms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 8, 2011
14 years ago
Most Recent CVE
Apr 10, 2025
471 days ago

CVE Severity & Scoring

Bluecms12 CVEs
All CVEs352,427 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network11 (91.7%)
Unknown1 (8.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (91.7%)
High0 (0.0%)
Unknown1 (8.3%)
User Interaction
None11 (91.7%)
Unknown1 (8.3%)
Required0 (0.0%)
Privileges Required
Low1 (8.3%)
High1 (8.3%)
None9 (75.0%)
Unknown1 (8.3%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Bluecms 1.6 has SQL injection in line 132 of admin/area.php
Aug 23, 20229.838NONO
BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.
May 30, 20239.830NONO
BlueCMS 1.6 has SQL injection in line 55 of admin/model.php
Aug 23, 20229.830NONO
BlueCMS 1.6 has SQL injection in line 132 of admin/article.php
Aug 23, 20229.830NONO
BlueCMS v1.6 contains a SQL injection vulnerability via /ad_js.php.
Sep 8, 20219.830NONO
A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resul
Mar 28, 20199.830NONO
BlueCMS 1.6 allows SQL Injection via the user_name parameter to uploads/user.php?act=index_login.
Sep 4, 20189.829NONO
Bluecms 1.6 has a SQL injection vulnerability at cooike.
May 3, 20229.828NONO
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
Mar 6, 20199.824NONO
SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action.
Oct 8, 20117.521NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Bluecms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6128.72.1%00