Vulnerability index

Browse CVEs

12 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Joyplus Cms HIGH 7.5
CVE-2020-20636

SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad…

Mitigation only
Fix from $1,950 2023-06-20
Joyplus Cms HIGH 7.5
CVE-2020-22124

A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.

No fix yet
Fix from $1,950 2021-08-18
Joyplus Cms HIGH 7.5
CVE-2019-17175

joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.

No fix yet
Fix from $1,950 2019-10-04
Joyplus Cms MEDIUM 6.1
CVE-2018-14500

joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.

No fix yet
Fix from $1,600 2018-07-22
Joyplus Cms CRITICAL 9.8
CVE-2018-14389

joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.

No fix yet
Fix from $2,300 2018-07-18
Joyplus Cms MEDIUM 5.4
CVE-2018-14388

joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.

No fix yet
Fix from $1,600 2018-07-18
Joyplus Cms CRITICAL 9.8
CVE-2018-14334

manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm va…

No fix yet
Fix from $2,300 2018-07-17
Joyplus Cms MEDIUM 6.1
CVE-2018-12905EPSS 42%

joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.

No fix yet
Fix from $1,600 2018-06-27
Joyplus Cms CRITICAL 9.8
CVE-2018-12039

joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/…

No fix yet
Fix from $2,300 2018-06-07
Joyplus Cms MEDIUM 5.3
CVE-2018-10028

joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.

Mitigation only
Fix from $1,600 2018-04-11
Joyplus Cms CRITICAL 9.8
CVE-2018-8766

joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.p…

No fix yet
Fix from $2,300 2018-03-18
Joyplus Cms HIGH 8.8
CVE-2018-8717

joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

No fix yet
Fix from $1,950 2018-03-15