A weakness has been identified in PbootCMS up to 3.2.22, affecting the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.
CVE-2026-79387 is a SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5. An authenticated user can modify arbitrary user account fields, including passwords and roles, via crafted parameters to the User/mod interface. This vulnerability allows for potential elevation of privileges and account takeover. Defenders responsible for PbootCMS deployments, particularly those with authenticated u [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T22:17:26.020Z and has not been modified since then. PbootCMS v.3.2.15 is vulnerable to arbitrary code execution via multiple components, including MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php, with a CVSS score of 9.8, indicating critical [truncated]
A code injection vulnerability has been identified in PbootCMS v.3.2.11 within its site configuration functionality. The vulnerability was published to the CVE Program on 26 May 2026. At this time, no CVSS score or severity rating has been assigned by NVD, and the vulnerability has not been added to CISA's Known Exploited Vulnerabilities (KEV) catalog. The vendor attribution is currently marked as requiri [truncated]