CVE-2018-18308: Bigtreecms Bigtree CMS

Medium severity, CVSS 6.1. EPSS: 3.6% chance of exploitation in the next 30 days.

In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).

Affected products

Published 2018-10-16. Last modified 2026-06-17.