Ayacms Project's vulnerability footprint concentrates in a single content-management system product and skews strongly toward critical-severity outcomes, reflecting the inherent risks of a web-facing application handling user input and file uploads. The recurring weakness classes—including code injection, argument injection, unrestricted file uploads, and cross-site request forgery—characterize a system where input validation and access control present the durable structural risk to defenders. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ayacms Project over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-47926CRITICAL AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php | Dec 22, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-46102CRITICAL AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php | Dec 22, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-45550CRITICAL AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE). | Dec 7, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-43074CRITICAL AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary | Nov 10, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-46101HIGH AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code. | Dec 22, 2022 | 8.8 | 28 | NO | NO |
CVE-2022-45548HIGH AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. | Dec 6, 2022 | 8.8 | 28 | NO | NO |
CVE-2020-23686HIGH Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts. | Nov 2, 2021 | 8.8 | 26 | NO | NO |
CVE-2022-48116HIGH AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php. | Jan 27, 2023 | 7.2 | 24 | NO | NO |
CVE-2021-44238HIGH AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php, | Mar 1, 2022 | 7.2 | 24 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ayacms Project.
Media articles that mention a CVE ID that affects a product developed by Ayacms Project — matched by CVE ID, not by vendor name.