Vulnerabilities (CVE)

Filtered by vendor Bosscms Subscribe
Filtered by product Bosscms
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-31609 1 Bosscms 1 Bosscms 2025-04-18 N/A 7.1 HIGH
Cross Site Scripting (XSS) vulnerability in BOSSCMS v3.10 allows attackers to run arbitrary code via the header code and footer code fields in code configuration.
CVE-2022-44937 1 Bosscms 1 Bosscms 2024-11-21 N/A 6.5 MEDIUM
Bosscms v2.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the Add function under the Administrator List module.
CVE-2022-28606 1 Bosscms 1 Bosscms 2024-11-21 7.5 HIGH 9.8 CRITICAL
An arbitrary file upload vulnerability exists in Wenzhou Huoyin Information Technology Co., Ltd. BossCMS 1.0, which can be exploited by an attacker to gain control of the server.