Pmb

Vendor:

First CVE: Jun 23, 2022 · Active for 4 years

23
Total CVEs
More Total CVEs than 95% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pmb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 23, 2022
4 years ago
Most Recent CVE
Dec 23, 2025
216 days ago

CVE Severity & Scoring

Pmb23 CVEs
All CVEs352,785 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low0 (0.0%)
High3 (13.0%)
None20 (87.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file.
Mar 6, 20239.840NONO
An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file.
Nov 25, 20259.833NONO
File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file.
Jan 11, 20247.230NONO
PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php.
Mar 6, 20239.830NONO
PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php.
Jun 23, 20226.130NOYES
In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution.
May 27, 20259.829NONO
SIGB PMB before 8.0.1.2 allows SQL injection.
May 27, 20259.829NONO
Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access t
Jan 16, 20259.829NONO
PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php.
Mar 6, 20236.129NOYES
PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external
Mar 6, 20236.129NOYES

Exploit Exposure

Signals from CVEs in this product scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
17.4% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (23 CVEs).

Media Mentions

Signals from CVEs in this product scope (23 CVEs).

Top CNAs Publishing CVEs For Pmb

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0.1.1428.20.3%00
7.4.667.64.4%03
7.3.1016.12.1%01