CVE-2017-9546: Bigtreecms Bigtree CMS

Medium severity, CVSS 5.7. EPSS: 1.1% chance of exploitation in the next 30 days.

admin.php in BigTree through 4.2.18 allows remote authenticated users to cause a denial of service (inability to save revisions) via XSS sequences in a revision name.

Affected products

  • Bigtreecms Bigtree CMS: up to and including 4.2.18

Published 2017-06-12. Last modified 2026-06-17.