Skip to main content

Vendor/product archive

bluecms_project / bluecms CVEs

Beta · best-effort

12 CVEs tagged to bluecms_project / bluecms9 Critical, 1 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-29150

Published Apr 10, 2025

BlueCMS 1.6 suffers from Arbitrary File Deletion via the id parameter in an /publish.php?act=del request.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45894

Published Oct 7, 2024

BlueCMS 1.6 suffers from Arbitrary File Deletion via the file_name parameter in an /admin/database.php?act=del request.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-33734

Published May 30, 2023

BlueCMS v1.6 was discovered to contain a SQL injection vulnerability via the keywords parameter at search.php.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10262

Published Mar 28, 2019

A SQL Injection issue was discovered in BlueCMS 1.6. The variable $ad_id is spliced directly in uploads/admin/ad.php in the admin folder, and is not wrapped in single quotes, resu…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9594

Published Mar 6, 2019

BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2010-4897

Published Oct 8, 2011

SQL injection vulnerability in comment.php in BlueCMS 1.6 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header in a send action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1