VendorsFeehifeehicmsall versions
Vulnerabilities

Feehi FeehiCMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2020-21322
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
Published 2021-09-15 · Modified
9.8EPSS 0.018
CVE-2020-21489
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
Published 2023-06-20 · Modified
9.8EPSS 0.013
CVE-2020-21174
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
Published 2023-06-20 · Modified
9.8EPSS 0.013
CVE-2020-21516
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
Published 2022-09-06 · Modified
9.8EPSS 0.012
CVE-2024-8294
FeehiCMS index.php update unrestricted upload
Published 2024-08-29 · Analyzed
9.8EPSS 0.008
CVE-2024-8295
FeehiCMS index.php createBanner unrestricted upload
Published 2024-08-29 · Analyzed
9.8EPSS 0.008
CVE-2024-8296
FeehiCMS index.php insert unrestricted upload
Published 2024-08-29 · Analyzed
9.8EPSS 0.008
CVE-2025-15264
FeehiCMS TimThumb timthumb.php server-side request forgery
Published 2025-12-30 · Analyzed
7.5EPSS 0.004
CVE-2025-65657
FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in an executable location) without sufficient validation, sanitization, or execution restrictions. An authenticated remote attacker can upload a crafted PHP file and cause the application or web server to execute it, resulting in remote code execution (RCE).
Published 2025-12-02 · Analyzed
6.5EPSS 0.004
CVE-2025-63523
FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend accepts the changes. This can lead to unintended username changes.
Published 2025-12-01 · Analyzed
6.5EPSS 0.003
CVE-2020-19709
Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.
Published 2021-08-26 · Modified
6.1EPSS 0.006
CVE-2020-36607
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
Published 2022-12-15 · Modified
6.1EPSS 0.006
CVE-2020-20589
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
Published 2022-12-15 · Modified
6.1EPSS 0.006
CVE-2022-43320
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.
Published 2022-11-09 · Modified
6.1EPSS 0.004
CVE-2021-36572
Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.
Published 2022-12-15 · Modified
6.1EPSS 0.004
CVE-2025-63520
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate).
Published 2025-12-01 · Analyzed
6.1EPSS 0.002
CVE-2022-40000
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.
Published 2022-12-15 · Modified
5.4EPSS 0.005
CVE-2022-40001
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.
Published 2022-12-15 · Modified
5.4EPSS 0.005
CVE-2022-40002
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.
Published 2022-12-15 · Modified
5.4EPSS 0.005
CVE-2022-40373
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.
Published 2022-12-15 · Modified
5.4EPSS 0.005
CVE-2021-36573
File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.
Published 2022-12-15 · Modified
5.4EPSS 0.005
CVE-2022-40408
FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.
Published 2022-09-29 · Modified
5.4EPSS 0.005
CVE-2025-63522
Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function
Published 2025-12-01 · Analyzed
4.6EPSS 0.002
CVE-2022-4014
FeehiCMS Post My Comment Tab cross-site request forgery
Published 2022-11-16 · Modified
4.3EPSS 0.002