Pbootcms is a web content management system whose vulnerability profile concentrates entirely in its core product and skews strongly toward critical-severity outcomes. The exposure recurs persistently through application-layer weakness classes including SQL injection, cross-site scripting, CSRF, code injection, and forced browsing—a pattern characteristic of web applications with insufficient input validation, output encoding, and request-origin verification. These vulnerabilities reflect the parser and templating demands of a CMS serving as an entry point to hosted content and backend services. Defenders deploying this platform should prioritize network segmentation, access controls, and tight patching discipline; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pbootcms over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-32417CRITICAL PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php. | Jul 14, 2022 | 9.8 | 48 | NO | NO |
CVE-2021-37497CRITICAL SQL injection vulnerability in route of PbootCMS 3.0.5 allows remote attackers to run arbitrary SQL commands via crafted GET request. | Feb 3, 2023 | 9.8 | 31 | NO | NO |
CVE-2018-16356CRITICAL An issue was discovered in PbootCMS. There is a SQL injection via the api.php/List/index order parameter. | Mar 2, 2020 | 9.8 | 31 | NO | NO |
CVE-2018-19595CRITICAL PbootCMS V1.3.1 build 2018-11-14 allows remote attackers to execute arbitrary code via use of "eval" with mixed case, as demonstrated by an index.php/list/5/?current={pboot:if(evAl | Nov 27, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-10133CRITICAL PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\Par | Apr 16, 2018 | 9.8 | 31 | NO | NO |
CVE-2020-23580CRITICAL Remote Code Execution vulnerability in PbootCMS 2.0.8 in the message board. | Jul 8, 2021 | 9.8 | 30 | NO | NO |
CVE-2018-16357CRITICAL An issue was discovered in PbootCMS. There is a SQL injection via the api.php/Cms/search order parameter. | Mar 2, 2020 | 9.8 | 30 | NO | NO |
CVE-2018-18450CRITICAL apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/ | Oct 17, 2018 | 9.8 | 30 | NO | NO |
CVE-2024-12789CRITICAL A vulnerability was found in PbootCMS up to 3.2.3. It has been classified as critical. This affects an unknown part of the file apps/home/controller/IndexController.php. The manipu | Dec 19, 2024 | 9.8 | 29 | NO | NO |
CVE-2018-19893CRITICAL SearchController.php in PbootCMS 1.2.1 has SQL injection via the index.php/Search/index.html query string. | Dec 6, 2018 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pbootcms.
Media articles that mention a CVE ID that affects a product developed by Pbootcms — matched by CVE ID, not by vendor name.