CVE-2019-8421: Bagesoft Bagecms

High severity, CVSS 7.2. EPSS: 1.2% chance of exploitation in the next 30 days.

upload/protected/modules/admini/views/post/index.php in BageCMS through 3.1.4 allows SQL Injection via the title or titleAlias parameter.

Affected products

  • Bagesoft Bagecms: up to and including 3.1.4

Published 2019-02-17. Last modified 2026-06-17.