Baowzh's vulnerability footprint centers on a narrowly scoped product line, with the primary focus on its hfly application. The durable signal reflects a pattern of web-application input-handling and access-control issues, including path traversal, code injection, cross-site scripting, and improper file-upload controls, which are characteristic of application-layer design and validation gaps. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baowzh over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-14522CRITICAL A vulnerability was detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The impacted element is an unknown function of the file /Public/Kindeditor/php/upload_js | Dec 11, 2025 | 9.8 | 29 | NO | NO |
CVE-2025-14520CRITICAL A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/index.php/datafile/delfile. This ma | Dec 11, 2025 | 9.1 | 27 | NO | NO |
CVE-2025-14521HIGH A security vulnerability has been detected in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. The affected element is an unknown function of the file /admin/index.php/d | Dec 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-14519MEDIUM A security flaw has been discovered in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. This issue affects some unknown processing of the file /admin/index.php/advtext/a | Dec 11, 2025 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baowzh.
Media articles that mention a CVE ID that affects a product developed by Baowzh — matched by CVE ID, not by vendor name.