Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fiyo Cms MEDIUM 6.1
CVE-2020-35373

In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.

No fix yet
Fix from $1,600 2021-06-17
Fiyo Cms MEDIUM 6.1
CVE-2018-18545

Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.

No fix yet
Fix from $1,600 2018-10-21
Fiyo Cms HIGH 8.8
CVE-2017-17103

Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from nor…

Patch available
Fix from $1,950 2017-12-04
Fiyo Cms HIGH 7.5
CVE-2017-17102

Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].

Patch available
Fix from $1,950 2017-12-04
Fiyo Cms HIGH 7.5
CVE-2017-17104

Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].

Patch available
Fix from $1,950 2017-12-04
Fiyo Cms CRITICAL 9.8
CVE-2015-3934

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to app…

No fix yet
Fix from $2,300 2017-11-21
Fiyo Cms CRITICAL 9.8
CVE-2014-9148EPSS 11%

Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administ…

Fix: after 2.0.1.8
Fix from $2,300 2017-10-16
Fiyo Cms HIGH 7.5
CVE-2014-9147EPSS 11%

Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

Fix: after 2.0.1.8
Fix from $1,950 2017-10-16
Fiyo Cms MEDIUM 6.1
CVE-2017-13778

Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.

Patch available
Fix from $1,600 2017-08-30
Fiyo Cms CRITICAL 9.8
CVE-2017-11631

dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.

Patch available
Fix from $2,300 2017-07-26
Fiyo Cms HIGH 7.5
CVE-2017-11630

dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences i…

Patch available
Fix from $1,950 2017-07-26
Fiyo Cms CRITICAL 9.8
CVE-2017-11412

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11413

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id'].

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11414

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_P…

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11415

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level…

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11416

Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11417

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11418

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iS…

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11419

Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].

Patch available
Fix from $2,300 2017-07-18
Fiyo Cms CRITICAL 9.8
CVE-2017-11354

Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.

Patch available
Fix from $2,300 2017-07-17
Fiyo Cms HIGH 7.5
CVE-2017-8853

Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file param…

Patch available
Fix from $1,950 2017-05-09
Fiyo Cms CRITICAL 9.8
CVE-2017-7625

In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execu…

No fix yet
Fix from $2,300 2017-04-10
Fiyo Cms HIGH 8.8
CVE-2017-6823EPSS 8%

Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.

No fix yet
Fix from $1,950 2017-03-12
Fiyo Cms HIGH 7.5
CVE-2014-9145

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an ed…

No fix yet
Fix from $1,950 2015-04-14