Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2020-35373 In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack. Fiyo Cms No fix yet Fix from $1,6002021-06-17 MEDIUM 6.1 CVE-2018-18545 Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter. Fiyo Cms No fix yet Fix from $1,6002018-10-21 HIGH 8.8 CVE-2017-17103 Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from nor… Fiyo Cms Patch available Fix from $1,9502017-12-04 HIGH 7.5 CVE-2017-17102 Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link']. Fiyo Cms Patch available Fix from $1,9502017-12-04 HIGH 7.5 CVE-2017-17104 Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name']. Fiyo Cms Patch available Fix from $1,9502017-12-04 CRITICAL 9.8 CVE-2015-3934 Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to app… Fiyo Cms No fix yet Fix from $2,3002017-11-21 CRITICAL 9.8 CVE-2014-9148EPSS 11% Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administ… Fiyo Cms after 2.0.1.8 Fix from $2,3002017-10-16 HIGH 7.5 CVE-2014-9147EPSS 11% Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. Fiyo Cms after 2.0.1.8 Fix from $1,9502017-10-16 MEDIUM 6.1 CVE-2017-13778 Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter. Fiyo Cms Patch available Fix from $1,6002017-08-30 CRITICAL 9.8 CVE-2017-11631 dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter. Fiyo Cms Patch available Fix from $2,3002017-07-26 HIGH 7.5 CVE-2017-11630 dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences i… Fiyo Cms Patch available Fix from $1,9502017-07-26 CRITICAL 9.8 CVE-2017-11412 Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id']. Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11413 Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id']. Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11414 Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_P… Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11415 Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level… Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11416 Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11417 Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id']. Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11418 Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iS… Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11419 Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title']. Fiyo Cms Patch available Fix from $2,3002017-07-18 CRITICAL 9.8 CVE-2017-11354 Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name. Fiyo Cms Patch available Fix from $2,3002017-07-17 HIGH 7.5 CVE-2017-8853 Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file param… Fiyo Cms Patch available Fix from $1,9502017-05-09 CRITICAL 9.8 CVE-2017-7625 In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execu… Fiyo Cms No fix yet Fix from $2,3002017-04-10 HIGH 8.8 CVE-2017-6823EPSS 8% Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. Fiyo Cms No fix yet Fix from $1,9502017-03-12 HIGH 7.5 CVE-2014-9145 Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an ed… Fiyo Cms No fix yet Fix from $1,9502015-04-14