Vulnerabilities > Bigtreecms > Bigtree CMS > 4.4.16

DATE CVE VULNERABILITY TITLE RISK
2022-08-03 CVE-2022-36197 Cross-site Scripting vulnerability in Bigtreecms Bigtree CMS 4.4.16
BigTree CMS 4.4.16 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted PDF file.
network
low complexity
bigtreecms CWE-79
5.4