Pmb
Vendor:
First CVE: Jun 23, 2022 · Active for 4 years
23
Total CVEs
More Total CVEs than 95% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pmb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 23, 2022
4 years ago
Most Recent CVE
Dec 23, 2025
216 days ago
CVE Severity & Scoring
Pmb23 CVEs
22%
30%
48%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None19 (82.6%)
Unknown0 (0.0%)
Required4 (17.4%)
Privileges Required
Low0 (0.0%)
High3 (13.0%)
None20 (87.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-24734CRITICAL An arbitrary file upload vulnerability in the camera_upload.php component of PMB v7.4.6 allows attackers to execute arbitrary code via a crafted image file. | Mar 6, 2023 | 9.8 | 40 | NO | NO |
CVE-2025-61168CRITICAL An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializing an arbitrary file. | Nov 25, 2025 | 9.8 | 33 | NO | NO |
CVE-2023-46474HIGH File Upload vulnerability PMB v.7.4.8 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted PHP file uploaded to the start_import.php file. | Jan 11, 2024 | 7.2 | 30 | NO | NO |
CVE-2023-24736CRITICAL PMB v7.4.6 was discovered to contain a remote code execution (RCE) vulnerability via the component /sauvegarde/restaure_act.php. | Mar 6, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-34328MEDIUM PMB 7.3.10 allows reflected XSS via the id parameter in an lvl=author_see request to index.php. | Jun 23, 2022 | 6.1 | 30 | NO | YES |
CVE-2025-48744CRITICAL In SIGB PMB before 8.0.1.2, attackers can achieve Local File Inclusion and remote code execution. | May 27, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-48743CRITICAL SIGB PMB before 8.0.1.2 allows SQL injection. | May 27, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-0471CRITICAL Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability could allow an attacker to upload a file to gain remote access t | Jan 16, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-24737MEDIUM PMB v7.4.6 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the query parameter at /admin/convert/export_z3950.php. | Mar 6, 2023 | 6.1 | 29 | NO | YES |
CVE-2023-24735MEDIUM PMB v7.4.6 was discovered to contain an open redirect vulnerability via the component /opac_css/pmb.php. This vulnerability allows attackers to redirect victim users to an external | Mar 6, 2023 | 6.1 | 29 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
17.4% of CVEs· 98th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Pmb
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.0.1.14 | 2 | 8.2 | 0.3% | 0 | 0 |
| 7.4.6 | 6 | 7.6 | 4.4% | 0 | 3 |
| 7.3.10 | 1 | 6.1 | 2.1% | 0 | 1 |