CVE-2017-7695: Bigtreecms Bigtree CMS

Critical severity, CVSS 9.8. EPSS: 2% chance of exploitation in the next 30 days.

Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.

Affected products

  • Bigtreecms Bigtree CMS: up to and including 4.2.16

Published 2017-04-11. Last modified 2026-06-17.