VendorsFiyofiyo_cmsall versions
Vulnerabilities

Fiyo Fiyo CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

26CVEs
CVE-2014-9148
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.
Published 2017-10-16 · Modified
9.81 PoCEPSS 0.114
CVE-2017-7625
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
Published 2017-04-10 · Modified
9.8EPSS 0.032
CVE-2015-3934
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.
Published 2017-11-21 · Modified
9.81 PoCEPSS 0.031
CVE-2017-11631
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
Published 2017-07-26 · Modified
9.8EPSS 0.010
CVE-2017-11417
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11413
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id'].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11415
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level'].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11419
Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11418
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11416
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11414
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11412
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].
Published 2017-07-18 · Modified
9.8EPSS 0.010
CVE-2017-11354
Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.
Published 2017-07-17 · Modified
9.8EPSS 0.010
CVE-2017-6823
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.
Published 2017-03-12 · Modified
8.81 PoCEPSS 0.080
CVE-2017-17103
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.
Published 2017-12-04 · Modified
8.8EPSS 0.012
CVE-2017-17104
Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].
Published 2017-12-04 · Modified
7.8EPSS 0.017
CVE-2014-9147
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.
Published 2017-10-16 · Modified
7.51 PoCEPSS 0.114
CVE-2014-9145
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.
Published 2015-04-14 · Modified
7.51 PoCEPSS 0.021
CVE-2017-11630
dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.
Published 2017-07-26 · Modified
7.5EPSS 0.018
CVE-2017-8853
Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file parameter during an act=db action.
Published 2017-05-09 · Modified
7.5EPSS 0.014
CVE-2017-17102
Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].
Published 2017-12-04 · Modified
7.5EPSS 0.011
CVE-2018-18545
Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.
Published 2018-10-21 · Modified
6.1EPSS 0.008
CVE-2020-35373
In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.
Published 2021-06-17 · Modified
6.1EPSS 0.007
CVE-2017-13778
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.
Published 2017-08-30 · Modified
6.1EPSS 0.006
CVE-2014-9146
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) id, (3) page, or (4) app parameter to the default URI or the (5) act parameter to dapur/index.php.
Published 2015-04-14 · Modified
4.31 PoCEPSS 0.025
CVE-2014-4032
Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the Nama field.
Published 2014-06-11 · Modified
4.3EPSS 0.019