hyphp records
4 published records for vendor hyphp.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-434 Unrestricted Upload of File with Dangerous Type1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2022-24677No exploit | Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.hyphp · hybbs2 | Critical9.8 | — | 2.5% | Feb 8, 2022 |
35Monitor | CVE-2022-24676No exploit | update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.hyphp · hybbs2 · CWE-434 | High8.8 | — | 1.5% | Feb 8, 2022 |
35Monitor | CVE-2019-10644No exploit | An issue was discovered in HYBBS 2.2.hyphp · hybbs · CWE-352 | High8.8 | — | 0.7% | Mar 29, 2019 |
24Monitor | CVE-2018-14499No exploit | An issue was found in HYBBS through 2016-03-08.hyphp · hybbs · CWE-79 | Medium6.1 | — | 0.8% | Mar 7, 2019 |
- CVE-2022-2467740Plan
Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.
CriticalCVSS 9.8No exploitEPSS 2%hyphp · hybbs2Feb 8, 2022
- CVE-2022-2467635Monitor
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
HighCVSS 8.8No exploitEPSS 1%hyphp · hybbs2Feb 8, 2022
- CVE-2019-1064435Monitor
An issue was discovered in HYBBS 2.2.
HighCVSS 8.8No exploitEPSS 1%hyphp · hybbsMar 29, 2019
- CVE-2018-1449924Monitor
An issue was found in HYBBS through 2016-03-08.
MediumCVSS 6.1No exploitEPSS 1%hyphp · hybbsMar 7, 2019