Bosscms is a content management system product with a vulnerability profile centered on web application security issues endemic to dynamic content platforms. The recurring weakness classes—including cross-site request forgery, cross-site scripting, improper authorization, and unrestricted file uploads—reflect common input-validation and access-control challenges in web application design. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bosscms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-28606CRITICAL An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server. | May 5, 2022 | 9.8 | 29 | NO | NO |
CVE-2024-22938HIGH Insecure Permissions vulnerability in BossCMS v.1.3.0 allows a local attacker to execute arbitrary code and escalate privileges via the init function in admin.class.php component. | Jan 30, 2024 | 7.8 | 22 | NO | NO |
CVE-2022-44937MEDIUM Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module. | Nov 28, 2022 | 6.5 | 22 | NO | NO |
CVE-2024-31609HIGH Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration. | Apr 25, 2024 | 7.1 | 20 | NO | NO |
CVE-2024-31613MEDIUM BOSSCMS v3.10 is vulnerable to Cross Site Request Forgery (CSRF) in name="head_code" or name="foot_code." | Jun 10, 2024 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bosscms.
Media articles that mention a CVE ID that affects a product developed by Bosscms — matched by CVE ID, not by vendor name.