VendorsFeng Officefeng_officeall versions
Vulnerabilities

Feng Office Feng Office

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2019-9623
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
Published 2019-03-07 · Modified
9.81 PoCEPSS 0.081
CVE-2024-6039
Feng Office Workspaces sql injection
Published 2024-06-16 · Modified
8.81 PoCEPSS 0.007
CVE-2025-5877
Fengoffice Feng Office Document Upload ApplicationDataObject.class.php xml external entity reference
Published 2025-06-09 · Analyzed
8.1EPSS 0.004
CVE-2011-3738
Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.
Published 2011-09-23 · Modified
5.0EPSS 0.013
CVE-2014-5343
Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.
Published 2014-08-19 · Modified
4.3EPSS 0.019
CVE-2013-5744
Cross-site scripting (XSS) vulnerability in Feng Office 2.3.2-rc and earlier allows remote attackers to inject arbitrary web script or HTML via an arbitrary ref_XXX parameter.
Published 2013-10-28 · Modified
4.3EPSS 0.010