Sigb maintains a focused product line centered on PMB, a web-based application that has drawn a concentrated vulnerability footprint despite modest volume. The exposure skews strongly toward critical-severity outcomes and frequently acquires public exploit tooling, reflecting the application's web-facing role and the particular severity of its recurring weakness classes. Vulnerabilities cluster around input-handling and deserialization flaws—SQL injection, unrestricted file upload, cross-site scripting, and untrusted deserialization—alongside exposure of sensitive information, patterns typical of applications where user input flows directly into server-side logic and data handling without sufficient sanitization. Defenders should prioritize patches for this vendor's advisories and treat internet-reachable instances of PMB as high-risk; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sigb over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24734CRITICAL An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file. | Mar 6, 2023 | 9.8 | 40 | NO | NO |
CVE-2025-61168CRITICAL An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file. | Nov 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2023-46474HIGH File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file. | Jan 11, 2024 | 7.2 | 30 | NO | NO |
CVE-2023-24736CRITICAL PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php. | Mar 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-34328MEDIUM PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php. | Jun 23, 2022 | 6.1 | 30 | NO | YES |
CVE-2025-48744CRITICAL In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution. | May 27, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-48743CRITICAL SIGB PMB before 8.0.1.2 allows SQL injection. | May 27, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-0471CRITICAL Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access t | Jan 16, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-24737MEDIUM PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php. | Mar 6, 2023 | 6.1 | 29 | NO | YES |
CVE-2023-24735MEDIUM PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external | Mar 6, 2023 | 6.1 | 29 | NO | YES |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sigb.
Media articles that mention a CVE ID that affects a product developed by Sigb — matched by CVE ID, not by vendor name.