Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2024-33445

    An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.

    Last Modified: Sep 22, 2025
    Published: Apr 29, 2024

    CVE-2020-28062

    An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote malicious user execute arbitrary code.

    Last Modified: Nov 21, 2024
    Published: Apr 04, 2022

    CVE-2020-21130

    Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.

    Last Modified: Nov 21, 2024
    Published: Jun 21, 2021

    CVE-2019-1010193

    hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).

    Last Modified: Nov 21, 2024
    Published: Jul 24, 2019

    CVE-2018-17826

    HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging app/common/model/AdminAnnex.php to add .php to the default list of allowable file-upload types (.jpg, .png, .gif, .jpeg, and .ico).

    Last Modified: Nov 21, 2024
    Published: Oct 01, 2018
    Items Per Page