CVE-2017-6914: Bigtreecms Bigtree CMS
High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.
CSRF exists in BigTree CMS 4.1.18 and 4.2.16 with the id parameter to the admin/ajax/users/delete/ page. A user can be deleted.
Affected products
- Bigtreecms Bigtree CMS: version 4.1.8 only; version 4.2.16 only
Published 2017-03-15. Last modified 2026-06-17.