CVE-2018-18450: Pbootcms
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
apps\admin\controller\content\SingleController.php in PbootCMS before V1.3.0 build 2018-11-12 has SQL Injection, as demonstrated by the POST data to the admin.php/Single/mod/mcode/1/id/3 URI.
Affected products
- Pbootcms Pbootcms: before 1.3.0 (fixed in 1.3.0)
Published 2018-10-17. Last modified 2026-06-17.