CVE-2017-9364: Bigtreecms Bigtree CMS
Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.
Affected products
- Bigtreecms Bigtree CMS: up to and including 4.2.18
Published 2017-06-02. Last modified 2026-06-17.