Vendors07FLY07flycmsall versions
Vulnerabilities

07FLY 07FlyCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2025-25379
Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.
Published 2025-02-28 · Analyzed
9.6EPSS 0.003
CVE-2024-9903
07FLYCMS/07FLY-CMS/07FlyCRM fileUpload unrestricted upload
Published 2024-10-12 · Analyzed
7.2EPSS 0.006
CVE-2024-9904
07FLYCMS/07FLY-CMS/07FlyCRM pictureUpload unrestricted upload
Published 2024-10-13 · Analyzed
7.2EPSS 0.006
CVE-2024-9855
07FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload
Published 2024-10-11 · Analyzed
7.2EPSS 0.006
CVE-2024-9856
07FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting
Published 2024-10-11 · Analyzed
5.1EPSS 0.004
CVE-2025-7078
07FLYCMS/07FLY-CMS/07FlyCRM cross-site request forgery
Published 2025-07-06 · Analyzed
5.0EPSS 0.003
CVE-2024-51156
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.
Published 2024-11-14 · Analyzed
4.7EPSS 0.002
CVE-2024-51157
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.
Published 2024-11-08 · Analyzed
4.7EPSS 0.002
CVE-2024-57159
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.
Published 2025-01-16 · Analyzed
3.5EPSS 0.002
CVE-2024-57611
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.
Published 2025-01-16 · Analyzed
3.5EPSS 0.002