Home/Product/uatech badaso
Product

uatech badaso

9 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-15398
<= 2.9.7
A security vulnerability has been detected in Uasoft badaso up to 2.9.7. Affected is the function forgetPassword of the file src/C
3.7LOW
CVE-2025-52353
all versions
An arbitrary code execution vulnerability in Badaso CMS 2.9.11. The Media Manager allows authenticated users to upload files conta
9.8CRITICAL
CVE-2023-38970
<= 2.9.7
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted
5.4MEDIUM
CVE-2023-38971
<= 2.9.7
Cross Site Scripting vulnerabiltiy in Badaso v.0.0.1 thru v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted
5.4MEDIUM
CVE-2023-38969
all versions
Cross Site Scripting vulnerabiltiy in Badaso v.2.9.7 allows a remote attacker to execute arbitrary code via a crafted payload to t
5.4MEDIUM
CVE-2023-38974
all versions
A stored cross-site scripting (XSS) vulnerability in the Edit Category function of Badaso v2.9.7 allows attackers to execute arbit
5.4MEDIUM
CVE-2023-38973
all versions
A stored cross-site scripting (XSS) vulnerability in the Add Tag function of Badaso v2.9.7 allows attackers to execute arbitrary w
5.4MEDIUM
CVE-2022-41705
all versions
Badaso version 2.6.3 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible
9.8CRITICAL
CVE-2022-41711
all versions
Badaso version 2.6.0 allows an unauthenticated remote attacker to execute arbitrary code remotely on the server. This is possible
9.8CRITICAL
threatengine.sh