Products: 1
    Vulnerabilities: 26
    Known Exploited: 0
    13
    Critical Level Threats
    8
    High Level Threats
    5
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-35373

    In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.

    Last Modified: Nov 21, 2024
    Published: Jun 17, 2021

    CVE-2018-18545

    Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.

    Last Modified: Nov 21, 2024
    Published: Oct 21, 2018

    CVE-2017-17102

    Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].

    Last Modified: Apr 20, 2025
    Published: Dec 04, 2017

    CVE-2017-17104

    Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].

    Last Modified: Apr 20, 2025
    Published: Dec 04, 2017

    CVE-2017-17103

    Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.

    Last Modified: Apr 20, 2025
    Published: Dec 04, 2017
    Items Per Page
    Fiyo Vulnerabilities & Security CVEs | CVE-DB