VendorsQianfoxfoxcmsall versions
Vulnerabilities

Qianfox Foxcms

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2024-12900
FoxCMS Configuration File installdb.php code injection
Published 2024-12-23 · Analyzed
9.8EPSS 0.007
CVE-2025-45238
foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.
Published 2025-05-05 · Analyzed
9.1EPSS 0.006
CVE-2025-6094
qianfox FoxCMS Download.php batchCope sql injection
Published 2025-06-15 · Analyzed
8.8EPSS 0.005
CVE-2025-7568
qianfox FoxCMS Video.php batchCope sql injection
Published 2025-07-14 · Analyzed
8.8EPSS 0.004
CVE-2024-12901
FoxCMS API Endpoint Site.php improper authorization
Published 2024-12-23 · Analyzed
6.9EPSS 0.006
CVE-2025-45240
foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.
Published 2025-05-05 · Analyzed
6.5EPSS 0.003
CVE-2025-11306
qianfox FoxCMS Search cross site scripting
Published 2025-10-05 · Analyzed
6.1EPSS 0.003
CVE-2025-51650
An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file.
Published 2025-07-14 · Analyzed
5.6EPSS 0.003
CVE-2025-45239
An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.
Published 2025-05-05 · Analyzed
5.3EPSS 0.007
CVE-2025-2653
FoxCMS improper authorization
Published 2025-03-23 · Analyzed
5.3EPSS 0.003