Ayacms

Vendor:

First CVE: Nov 2, 2021 · Active for 4 years

9
Total CVEs
More Total CVEs than 88% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
8.9
Avg CVSS
Higher Avg CVSS than 83% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ayacms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 2, 2021
4 years ago
Most Recent CVE
Jan 27, 2023
1,278 days ago

CVE Severity & Scoring

Ayacms9 CVEs
All CVEs353,240 CVEs
HighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low2 (22.2%)
High2 (22.2%)
None5 (55.6%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php
Dec 22, 20229.831NONO
AyaCMS 3.1.2 is vulnerable to Arbitrary file upload via /aya/module/admin/fst_down.inc.php
Dec 22, 20229.830NONO
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
Dec 7, 20229.830NONO
AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary
Nov 10, 20229.830NONO
AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code.
Dec 22, 20228.828NONO
AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability.
Dec 6, 20228.828NONO
Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts.
Nov 2, 20218.826NONO
AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.
Jan 27, 20237.224NONO
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,
Mar 1, 20227.224NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Ayacms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.1.298.91.1%00