Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Bijiadao

First CVE: Aug 20, 2018Active for: 8 yearsTotal CVEs: 9

Bijiadao develops a web-based content management system (Waimai Super CMS) that exhibits a durable pattern of input-handling and state-management vulnerabilities, with a particular concentration in cross-site scripting, SQL injection, and cross-site request forgery. Vulnerabilities affecting this vendor skew toward serious outcomes, reflecting the persistent challenge of sanitizing user input and managing session state in web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Bijiadao over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 2018
7 years ago
Most Recent CVE
Apr 15, 2019
2,657 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-3577CRITICAL
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI.
Jan 2, 20199.830NONO
CVE-2019-7585CRITICAL
An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public
Feb 7, 20199.829NONO
CVE-2018-16315MEDIUM
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
Sep 1, 20186.522NONO
CVE-2018-18261MEDIUM
In waimai Super Cms 20150505, there is an XSS vulnerability via the /admin.php/Foodcat/addsave fcname parameter.
Apr 15, 20196.121NONO
CVE-2018-18622MEDIUM
An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username parameter.
Oct 23, 20186.121NONO
CVE-2018-18082MEDIUM
XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI.
Oct 9, 20186.121NONO
CVE-2018-16157MEDIUM
waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=sa
Aug 30, 20185.320NONO
CVE-2019-7567MEDIUM
An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter.
Feb 7, 20196.119NONO
CVE-2018-15570MEDIUM
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
Aug 20, 20184.818NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
78%
22%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (33.3%)
Unknown0 (0.0%)
Required6 (66.7%)
Privileges Required
Low0 (0.0%)
High1 (11.1%)
None8 (88.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Bijiadao.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Bijiadao — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Bijiadao's Products

View all 1 CNAs →

Top CWEs