CVE-2017-9548: Bigtreecms Bigtree CMS
Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.
admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page that is scheduled for future publication (aka a pending page change).
Affected products
- Bigtreecms Bigtree CMS: up to and including 4.2.18
Published 2017-06-12. Last modified 2026-06-17.