Fengoffice

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 8
    Known Exploited: 0
    2
    Critical Level Threats
    0
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-36669

    An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.

    Last Modified: Aug 01, 2026
    Published: Jul 17, 2026

    CVE-2025-5877

    Fengoffice Feng Office Document Upload ApplicationDataObject.class.php xml external entity reference

    Last Modified: Jul 02, 2025
    Published: Jun 09, 2025

    CVE-2025-5433

    Fengoffice Feng Office index.php sql injection

    Last Modified: Apr 15, 2026
    Published: Jun 02, 2025

    CVE-2024-6039

    Feng Office Workspaces sql injection

    Last Modified: Nov 21, 2024
    Published: Jun 16, 2024

    CVE-2019-9623

    Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.

    Last Modified: Nov 21, 2024
    Published: Mar 07, 2019
    Items Per Page