Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Feehi Cms MEDIUM 5.4
CVE-2026-31313

An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbit…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31352

An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitr…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31353

An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31354

Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute ar…

No fix yet
Fix from $1,600 2026-04-06
Feehi Cms MEDIUM 5.4
CVE-2026-31350

An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via in…

No fix yet
Fix from $1,600 2026-04-06
Feehicms HIGH 7.3
CVE-2025-15264

A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThu…

Fix: after 2.1.1
Fix from $1,950 2025-12-30
Feehicms MEDIUM 6.5
CVE-2025-65657

FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote …

No fix yet
Fix from $1,600 2025-12-02
Feehicms MEDIUM 6.5
CVE-2025-63523

FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attack…

No fix yet
Fix from $1,600 2025-12-01
Feehicms MEDIUM 6.1
CVE-2025-63520

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).

No fix yet
Fix from $1,600 2025-12-01
Feehicms CRITICAL 9.8
CVE-2024-8296

A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=u…

Fix: after 2.1.1
Fix from $2,300 2024-08-29
Feehicms CRITICAL 9.8
CVE-2024-8295

A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /…

Fix: after 2.1.1
Fix from $2,300 2024-08-29
Feehicms CRITICAL 9.8
CVE-2024-8294

A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r…

Fix: after 2.1.1
Fix from $2,300 2024-08-29
Feehicms CRITICAL 9.8
CVE-2020-21174

File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.

Patch available
Fix from $2,300 2023-06-20
Feehicms CRITICAL 9.8
CVE-2020-21489

File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self …

Patch available
Fix from $2,300 2023-06-20
Feehicms MEDIUM 5.4
CVE-2022-40000

Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in p…

No fix yet
Fix from $1,600 2022-12-15
Feehicms MEDIUM 5.4
CVE-2022-40001

Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article pa…

No fix yet
Fix from $1,600 2022-12-15
Feehicms MEDIUM 5.4
CVE-2022-40002

Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.

No fix yet
Fix from $1,600 2022-12-15
Feehicms MEDIUM 5.4
CVE-2022-40373

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

No fix yet
Fix from $1,600 2022-12-15
Feehicms MEDIUM 6.1
CVE-2020-20589

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

No fix yet
Fix from $1,600 2022-12-15
Feehicms MEDIUM 6.1
CVE-2020-36607

Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.

No fix yet
Fix from $1,600 2022-12-15
Feehicms MEDIUM 6.1
CVE-2021-36572

Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.

Fix: after 2.1.1
Fix from $1,600 2022-12-15
Feehicms MEDIUM 5.4
CVE-2021-36573

File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.

Fix: after 2.1.1
Fix from $1,600 2022-12-15
Feehicms MEDIUM 6.1
CVE-2022-43320

FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fv…

No fix yet
Fix from $1,600 2022-11-09
Feehicms MEDIUM 5.4
CVE-2022-40408

FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Si…

No fix yet
Fix from $1,600 2022-09-29
Feehi Cms MEDIUM 6.1
CVE-2022-38796

A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing passwor…

No fix yet
Fix from $1,600 2022-09-14
Feehicms CRITICAL 9.8
CVE-2020-21516

There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.

Patch available
Fix from $2,300 2022-09-06
Feehi Cms MEDIUM 5.4
CVE-2022-34140

A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts…

No fix yet
Fix from $1,600 2022-07-28
Feehi Cms HIGH 8.8
CVE-2022-34971

An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a craf…

No fix yet
Fix from $1,950 2022-07-27
Feehicms CRITICAL 9.8
CVE-2020-21322

An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.

Fix: after 2.0.8
Fix from $2,300 2021-09-15
Feehicms MEDIUM 6.1
CVE-2020-19709

Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.

No fix yet
Fix from $1,600 2021-08-26