Bijiadao develops a web-based content management system (Waimai Super CMS) that exhibits a durable pattern of input-handling and state-management vulnerabilities, with a particular concentration in cross-site scripting, SQL injection, and cross-site request forgery. Vulnerabilities affecting this vendor skew toward serious outcomes, reflecting the persistent challenge of sanitizing user input and managing session state in web applications. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bijiadao over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3577CRITICAL An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/ProductAction.class.php allows blind SQL Injection via the id[0] parameter to the /product URI. | Jan 2, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-7585CRITICAL An issue was discovered in Waimai Super Cms 20150505. web/Lib/Action/PublicAction.class.php allows time-based SQL Injection via the param array parameter to the /index.php?m=public | Feb 7, 2019 | 9.8 | 29 | NO | NO |
CVE-2018-16315MEDIUM In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add. | Sep 1, 2018 | 6.5 | 22 | NO | NO |
CVE-2018-18261MEDIUM In waimai Super Cms 20150505, there is an XSS vulnerability via the /admin.php/Foodcat/addsave fcname parameter. | Apr 15, 2019 | 6.1 | 21 | NO | NO |
CVE-2018-18622MEDIUM An issue was discovered in Waimai Super Cms 20150505. There is XSS via the index.php?m=public&a=doregister username parameter. | Oct 23, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-18082MEDIUM XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI. | Oct 9, 2018 | 6.1 | 21 | NO | NO |
CVE-2018-16157MEDIUM waimai Super Cms 20150505 has a logic flaw allowing attackers to modify a price, before form submission, by observing data in a packet capture. By setting the index.php?m=cart&a=sa | Aug 30, 2018 | 5.3 | 20 | NO | NO |
CVE-2019-7567MEDIUM An issue was discovered in Waimai Super Cms 20150505. admin.php?m=Member&a=adminaddsave has XSS via the username or password parameter. | Feb 7, 2019 | 6.1 | 19 | NO | NO |
CVE-2018-15570MEDIUM In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter. | Aug 20, 2018 | 4.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bijiadao.
Media articles that mention a CVE ID that affects a product developed by Bijiadao — matched by CVE ID, not by vendor name.