CVE-2017-9365: Bigtreecms Bigtree CMS
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.
Affected products
- Bigtreecms Bigtree CMS: up to and including 4.2.18
Published 2017-06-02. Last modified 2026-06-17.