Boidcms is a modestly represented content management system with a narrow product scope whose vulnerabilities center on web application input handling and file management. The durable signal across its disclosures clusters around cross-site scripting, PHP remote file inclusion, and unrestricted file upload weaknesses—all classic vectors in PHP-based web applications—and the vendor's flaws have frequently acquired public exploit code. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boidcms over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-38836HIGH File Upload vulnerability in BoidCMS v.2.0.0 allows a remote attacker to execute arbitrary code by adding a GIF header to bypass MIME type checks. | Aug 21, 2023 | 8.8 | 82 | NO | YES |
CVE-2026-39387HIGH BoidCMS is an open-source, PHP-based flat-file CMS for building simple websites and blogs, using JSON as its database. Versions prior to 2.1.3 are vulnerable to a critical Local Fi | Apr 14, 2026 | 7.2 | 25 | NO | NO |
CVE-2024-32343MEDIUM A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the C | Apr 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-32342MEDIUM A cross-site scripting (XSS) vulnerability in the Create Page of Boid CMS v2.1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the P | Apr 17, 2024 | 6.1 | 18 | NO | NO |
CVE-2024-53255MEDIUM BoidCMS is a free and open-source flat file CMS for building simple websites and blogs, developed using PHP and uses JSON as a database. In affected versions a reflected Cross-site | Nov 25, 2024 | 5.4 | 17 | NO | NO |
CVE-2023-48824MEDIUM BoidCMS 2.0.1 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) issues via the title, subtitle, footer, or keywords parameter in a page=create action. | Dec 7, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boidcms.
Media articles that mention a CVE ID that affects a product developed by Boidcms — matched by CVE ID, not by vendor name.