Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pbootcms

First CVE: Apr 16, 2018Active for: 8 yearsTotal CVEs: 36
39.0
VTI Score
Medium

Pbootcms is a web content management system whose vulnerability profile concentrates entirely in its core product and skews strongly toward critical-severity outcomes. The exposure recurs persistently through application-layer weakness classes including SQL injection, cross-site scripting, CSRF, code injection, and forced browsing—a pattern characteristic of web applications with insufficient input validation, output encoding, and request-origin verification. These vulnerabilities reflect the parser and templating demands of a CMS serving as an entry point to hosted content and backend services. Defenders deploying this platform should prioritize network segmentation, access controls, and tight patching discipline; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pbootcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2018
8 years ago
Most Recent CVE
Dec 28, 2025
208 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2022-32417CRITICAL
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
Jul 14, 20229.848NONO
CVE-2021-37497CRITICAL
SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request.
Feb 3, 20239.831NONO
CVE-2018-16356CRITICAL
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter.
Mar 2, 20209.831NONO
CVE-2018-19595CRITICAL
PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl
Nov 27, 20189.831NONO
CVE-2018-10133CRITICAL
PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\Par
Apr 16, 20189.831NONO
CVE-2020-23580CRITICAL
Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board.
Jul 8, 20219.830NONO
CVE-2018-16357CRITICAL
An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter.
Mar 2, 20209.830NONO
CVE-2018-18450CRITICAL
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/
Oct 17, 20189.830NONO
CVE-2024-12789CRITICAL
A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipu
Dec 19, 20249.829NONO
CVE-2018-19893CRITICAL
SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string.
Dec 6, 20189.829NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
42%
25%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (2.8%)
Network35 (97.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (94.4%)
High2 (5.6%)
Unknown0 (0.0%)
User Interaction
None23 (63.9%)
Unknown0 (0.0%)
Required13 (36.1%)
Privileges Required
Low3 (8.3%)
High6 (16.7%)
None27 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pbootcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pbootcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pbootcms's Products

View all 2 CNAs →

Top CWEs