CVE-2017-9547: Bigtreecms Bigtree CMS

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching an Edit Page action and entering the Navigation Title or Page Title of a page that is scheduled for future publication (aka a pending page change).

Affected products

  • Bigtreecms Bigtree CMS: up to and including 4.2.18

Published 2017-06-12. Last modified 2026-06-17.