Mfscripts

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 15
    Known Exploited: 0
    2
    Critical Level Threats
    7
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-47899

    YetiShare File Hosting Script 5.1.0 Remote File Upload SSRF Vulnerability

    Last Modified: Apr 15, 2026
    Published: Jan 23, 2026

    CVE-2019-20060

    MFScripts YetiShare v3.5.2 through v4.5.4 places sensitive information in the Referer header. If this leaks, then third parties may discover password-reset hashes, file-delete links, or other sensitive information.

    Last Modified: Nov 21, 2024
    Published: Feb 10, 2020

    CVE-2019-20061

    The user-introduction email in MFScripts YetiShare v3.5.2 through v4.5.4 may leak the (system-picked) password if this email is sent in cleartext. In other words, the user is not allowed to choose their own initial password.

    Last Modified: Nov 21, 2024
    Published: Feb 10, 2020

    CVE-2019-20062

    MFScripts YetiShare v3.5.2 through v4.5.4 might allow an attacker to reset a password by using a leaked hash (the hash never expires until used).

    Last Modified: Nov 21, 2024
    Published: Feb 10, 2020

    CVE-2019-20059

    payment_manage.ajax.php and various *_manage.ajax.php in MFScripts YetiShare 3.5.2 through 4.5.4 directly insert values from the sSortDir_0 parameter into a SQL string. This allows an attacker to inject their own SQL and manipulate the query, typically extracting data from the database, aka SQL Injection. NOTE: this issue exists because of an incomplete fix for CVE-2019-19732.

    Last Modified: Nov 21, 2024
    Published: Feb 10, 2020
    Items Per Page
    Mfscripts Vulnerabilities & Security CVEs | CVE-DB