Feehi kayıtları
feehi üreticisine ait 36 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %13,9
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-434 Unrestricted Upload of File with Dangerous Type9
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-1021 Improper Restriction of Rendered UI Layers or Frames1
- CWE-863 Incorrect Authorization1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
36 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2020-21322İstismar yok | An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.feehi · feehicms · CWE-434 | Kritik9,8 | — | %1,8 | 15 Eyl 2021 |
39İzleyin | CVE-2020-21489İstismar yok | File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdfeehi · feehicms · CWE-434 | Kritik9,8 | — | %1,3 | 20 Haz 2023 |
39İzleyin | CVE-2020-21174İstismar yok | File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.feehi · feehicms · CWE-434 | Kritik9,8 | — | %1,3 | 20 Haz 2023 |
39İzleyin | CVE-2020-21516İstismar yok | There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP cofeehi · feehicms · CWE-434 | Kritik9,8 | — | %1,2 | 6 Eyl 2022 |
36İzleyin | CVE-2021-30108İstismar yok | Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability.feehi · feehi cms · CWE-918 | Kritik9,1 | — | %1,1 | 24 May 2021 |
35İzleyin | CVE-2022-34971İstismar yok | An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code vfeehi · feehi cms · CWE-434 | Yüksek8,8 | — | %1,2 | 26 Tem 2022 |
29İzleyin | CVE-2020-22643İstismar yok | Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution.feehi · feehi cms · CWE-434 | Yüksek7,2 | — | %1,9 | 26 Oca 2021 |
26İzleyin | CVE-2025-65657İstismar yok | FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management.feehi · feehicms · CWE-77 | Orta6,5 | — | %0,4 | 2 Ara 2025 |
26İzleyin | CVE-2025-63523İstismar yok | FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticatfeehi · feehicms · CWE-125 | Orta6,5 | — | %0,3 | 1 Ara 2025 |
24İzleyin | CVE-2020-21146İstismar yok | Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability.feehi · feehi cms · CWE-79 | Orta6,1 | — | %0,8 | 26 Oca 2021 |
24İzleyin | CVE-2020-36607İstismar yok | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tfeehi · feehicms · CWE-79 | Orta6,1 | — | %0,6 | 15 Ara 2022 |
24İzleyin | CVE-2020-19709İstismar yok | Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.feehi · feehicms · CWE-79 | Orta6,1 | — | %0,6 | 25 Ağu 2021 |
24İzleyin | CVE-2022-38796İstismar yok | A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header.feehi · feehi cms · CWE-74 | Orta6,1 | — | %0,6 | 14 Eyl 2022 |
24İzleyin | CVE-2020-20589İstismar yok | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tfeehi · feehicms · CWE-79 | Orta6,1 | — | %0,6 | 15 Ara 2022 |
24İzleyin | CVE-2021-36572İstismar yok | Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the loginfeehi · feehicms · CWE-79 | Orta6,1 | — | %0,4 | 15 Ara 2022 |
24İzleyin | CVE-2022-43320İstismar yok | FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?feehi · feehicms · CWE-79 | Orta6,1 | — | %0,4 | 9 Kas 2022 |
24İzleyin | CVE-2025-63520İstismar yok | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).feehi · feehicms · CWE-79 | Orta6,1 | — | %0,2 | 1 Ara 2025 |
22İzleyin | CVE-2022-34140Kavram kanıtı | A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary wefeehi · feehi cms · CWE-79 | Orta5,4 | — | %4,7 | 27 Tem 2022 |
22İzleyin | CVE-2025-15264İstismar yok | FeehiCMS TimThumb timthumb.php server-side request forgeryfeehi · feehicms · CWE-918 | Orta5,5 | — | %0,4 | 30 Ara 2025 |
21İzleyin | CVE-2024-8294İstismar yok | FeehiCMS index.php update unrestricted uploadfeehi · feehicms · CWE-434 | Orta5,3 | — | %0,8 | 29 Ağu 2024 |
21İzleyin | CVE-2024-8295İstismar yok | FeehiCMS index.php createBanner unrestricted uploadfeehi · feehicms · CWE-434 | Orta5,3 | — | %0,8 | 29 Ağu 2024 |
21İzleyin | CVE-2024-8296İstismar yok | FeehiCMS index.php insert unrestricted uploadfeehi · feehicms · CWE-434 | Orta5,3 | — | %0,8 | 29 Ağu 2024 |
21İzleyin | CVE-2022-40002İstismar yok | Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/feehi · feehicms · CWE-79 | Orta5,4 | — | %0,5 | 15 Ara 2022 |
21İzleyin | CVE-2022-40373İstismar yok | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.feehi · feehicms · CWE-79 | Orta5,4 | — | %0,5 | 15 Ara 2022 |
21İzleyin | CVE-2022-40001İstismar yok | Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create afeehi · feehicms · CWE-79 | Orta5,4 | — | %0,5 | 15 Ara 2022 |
- CVE-2020-2132240Planlayın
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
KritikCVSS 9,8İstismar yokEPSS %2feehi · feehicms15 Eyl 2021
- CVE-2020-2148939İzleyin
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupd
KritikCVSS 9,8İstismar yokEPSS %1feehi · feehicms20 Haz 2023
- CVE-2020-2117439İzleyin
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
KritikCVSS 9,8İstismar yokEPSS %1feehi · feehicms20 Haz 2023
- CVE-2020-2151639İzleyin
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP co
KritikCVSS 9,8İstismar yokEPSS %1feehi · feehicms6 Eyl 2022
- CVE-2021-3010836İzleyin
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability.
KritikCVSS 9,1İstismar yokEPSS %1feehi · feehi cms24 May 2021
- CVE-2022-3497135İzleyin
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code v
YüksekCVSS 8,8İstismar yokEPSS %1feehi · feehi cms26 Tem 2022
- CVE-2020-2264329İzleyin
Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution.
YüksekCVSS 7,2İstismar yokEPSS %2feehi · feehi cms26 Oca 2021
- CVE-2025-6565726İzleyin
FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management.
OrtaCVSS 6,5İstismar yokEPSS %0feehi · feehicms2 Ara 2025
- CVE-2025-6352326İzleyin
FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticat
OrtaCVSS 6,5İstismar yokEPSS %0feehi · feehicms1 Ara 2025
- CVE-2020-2114624İzleyin
Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability.
OrtaCVSS 6,1İstismar yokEPSS %1feehi · feehi cms26 Oca 2021
- CVE-2020-3660724İzleyin
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html t
OrtaCVSS 6,1İstismar yokEPSS %1feehi · feehicms15 Ara 2022
- CVE-2020-1970924İzleyin
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
OrtaCVSS 6,1İstismar yokEPSS %1feehi · feehicms25 Ağu 2021
- CVE-2022-3879624İzleyin
A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header.
OrtaCVSS 6,1İstismar yokEPSS %1feehi · feehi cms14 Eyl 2022
- CVE-2020-2058924İzleyin
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html t
OrtaCVSS 6,1İstismar yokEPSS %1feehi · feehicms15 Ara 2022
- CVE-2021-3657224İzleyin
Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login
OrtaCVSS 6,1İstismar yokEPSS %0feehi · feehicms15 Ara 2022
- CVE-2022-4332024İzleyin
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?
OrtaCVSS 6,1İstismar yokEPSS %0feehi · feehicms9 Kas 2022
- CVE-2025-6352024İzleyin
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).
OrtaCVSS 6,1İstismar yokEPSS %0feehi · feehicms1 Ara 2025
- CVE-2022-3414022İzleyin
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary we
OrtaCVSS 5,4Kavram kanıtıEPSS %5feehi · feehi cms27 Tem 2022
- CVE-2025-1526422İzleyin
FeehiCMS TimThumb timthumb.php server-side request forgery
OrtaCVSS 5,5İstismar yokEPSS %0feehi · feehicms30 Ara 2025
- CVE-2024-829421İzleyin
FeehiCMS index.php update unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1feehi · feehicms29 Ağu 2024
- CVE-2024-829521İzleyin
FeehiCMS index.php createBanner unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1feehi · feehicms29 Ağu 2024
- CVE-2024-829621İzleyin
FeehiCMS index.php insert unrestricted upload
OrtaCVSS 5,3İstismar yokEPSS %1feehi · feehicms29 Ağu 2024
- CVE-2022-4000221İzleyin
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/
OrtaCVSS 5,4İstismar yokEPSS %1feehi · feehicms15 Ara 2022
- CVE-2022-4037321İzleyin
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.
OrtaCVSS 5,4İstismar yokEPSS %1feehi · feehicms15 Ara 2022
- CVE-2022-4000121İzleyin
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create a
OrtaCVSS 5,4İstismar yokEPSS %1feehi · feehicms15 Ara 2022