CVE-2017-11736: Bigtreecms Bigtree CMS

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

SQL injection vulnerability in core\admin\auto-modules\forms\process.php in BigTree 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via the tags array parameter.

Affected products

Published 2017-07-29. Last modified 2026-06-17.