CVE-2017-6915: Bigtreecms Bigtree CMS

Medium severity, CVSS 4.3. EPSS: 0.4% chance of exploitation in the next 30 days.

CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.

Affected products

Published 2017-03-15. Last modified 2026-06-17.