İçeriğe atla
Noroxi

Feehi kayıtları

feehi üreticisine ait 36 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
8
Düzeltme kaydı olan
%13,9
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

36 kayıt
  • CVE-2020-21322
    40Planlayın

    An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.

    KritikCVSS 9,8İstismar yokEPSS %2

    feehi · feehicms15 Eyl 2021

  • CVE-2020-21489
    39İzleyin

    File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupd

    KritikCVSS 9,8İstismar yokEPSS %1

    feehi · feehicms20 Haz 2023

  • CVE-2020-21174
    39İzleyin

    File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.

    KritikCVSS 9,8İstismar yokEPSS %1

    feehi · feehicms20 Haz 2023

  • CVE-2020-21516
    39İzleyin

    There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP co

    KritikCVSS 9,8İstismar yokEPSS %1

    feehi · feehicms6 Eyl 2022

  • CVE-2021-30108
    36İzleyin

    Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability.

    KritikCVSS 9,1İstismar yokEPSS %1

    feehi · feehi cms24 May 2021

  • CVE-2022-34971
    35İzleyin

    An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code v

    YüksekCVSS 8,8İstismar yokEPSS %1

    feehi · feehi cms26 Tem 2022

  • CVE-2020-22643
    29İzleyin

    Feehi CMS 2.1.0 is affected by an arbitrary file upload vulnerability, potentially resulting in remote code execution.

    YüksekCVSS 7,2İstismar yokEPSS %2

    feehi · feehi cms26 Oca 2021

  • CVE-2025-65657
    26İzleyin

    FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management.

    OrtaCVSS 6,5İstismar yokEPSS %0

    feehi · feehicms2 Ara 2025

  • CVE-2025-63523
    26İzleyin

    FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticat

    OrtaCVSS 6,5İstismar yokEPSS %0

    feehi · feehicms1 Ara 2025

  • CVE-2020-21146
    24İzleyin

    Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability.

    OrtaCVSS 6,1İstismar yokEPSS %1

    feehi · feehi cms26 Oca 2021

  • CVE-2020-36607
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html t

    OrtaCVSS 6,1İstismar yokEPSS %1

    feehi · feehicms15 Ara 2022

  • CVE-2020-19709
    24İzleyin

    Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.

    OrtaCVSS 6,1İstismar yokEPSS %1

    feehi · feehicms25 Ağu 2021

  • CVE-2022-38796
    24İzleyin

    A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header.

    OrtaCVSS 6,1İstismar yokEPSS %1

    feehi · feehi cms14 Eyl 2022

  • CVE-2020-20589
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html t

    OrtaCVSS 6,1İstismar yokEPSS %1

    feehi · feehicms15 Ara 2022

  • CVE-2021-36572
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login

    OrtaCVSS 6,1İstismar yokEPSS %0

    feehi · feehicms15 Ara 2022

  • CVE-2022-43320
    24İzleyin

    FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?

    OrtaCVSS 6,1İstismar yokEPSS %0

    feehi · feehicms9 Kas 2022

  • CVE-2025-63520
    24İzleyin

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).

    OrtaCVSS 6,1İstismar yokEPSS %0

    feehi · feehicms1 Ara 2025

  • CVE-2022-34140
    22İzleyin

    A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary we

    OrtaCVSS 5,4Kavram kanıtıEPSS %5

    feehi · feehi cms27 Tem 2022

  • CVE-2025-15264
    22İzleyin

    FeehiCMS TimThumb timthumb.php server-side request forgery

    OrtaCVSS 5,5İstismar yokEPSS %0

    feehi · feehicms30 Ara 2025

  • CVE-2024-8294
    21İzleyin

    FeehiCMS index.php update unrestricted upload

    OrtaCVSS 5,3İstismar yokEPSS %1

    feehi · feehicms29 Ağu 2024

  • CVE-2024-8295
    21İzleyin

    FeehiCMS index.php createBanner unrestricted upload

    OrtaCVSS 5,3İstismar yokEPSS %1

    feehi · feehicms29 Ağu 2024

  • CVE-2024-8296
    21İzleyin

    FeehiCMS index.php insert unrestricted upload

    OrtaCVSS 5,3İstismar yokEPSS %1

    feehi · feehicms29 Ağu 2024

  • CVE-2022-40002
    21İzleyin

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/

    OrtaCVSS 5,4İstismar yokEPSS %1

    feehi · feehicms15 Ara 2022

  • CVE-2022-40373
    21İzleyin

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

    OrtaCVSS 5,4İstismar yokEPSS %1

    feehi · feehicms15 Ara 2022

  • CVE-2022-40001
    21İzleyin

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create a

    OrtaCVSS 5,4İstismar yokEPSS %1

    feehi · feehicms15 Ara 2022