Boyuncms Project maintains a single content-management system product that, despite modest prevalence, serves as a web-facing application where user input and data handling are critical attack surfaces. The recurring vulnerability profile centers on injection flaws, improper input validation, unsafe deserialization, code-injection conditions, and access-control weaknesses that are characteristic of web applications managing dynamic content and user interactions. Live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boyuncms Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-7100CRITICAL A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.p | Jul 7, 2025 | 9.8 | 27 | NO | NO |
CVE-2025-7102CRITICAL A vulnerability was found in BoyunCMS up to 1.4.20. It has been declared as critical. This vulnerability affects unknown code of the file application/update/controller/Server.php. | Jul 7, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-7101CRITICAL A vulnerability was found in BoyunCMS up to 1.4.20. It has been classified as critical. This affects an unknown part of the file /install/install_ok.php of the component Configurat | Jul 7, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-7103HIGH A vulnerability was found in BoyunCMS up to 1.4.20. It has been rated as critical. This issue affects some unknown processing of the file /application/pay/controller/Index.php of t | Jul 7, 2025 | 7.5 | 21 | NO | NO |
CVE-2025-7099MEDIUM A vulnerability has been found in BoyunCMS up to 1.21 on PHP7 and classified as critical. Affected by this vulnerability is an unknown functionality of the file install/install2.ph | Jul 7, 2025 | 5.9 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boyuncms Project.
Media articles that mention a CVE ID that affects a product developed by Boyuncms Project — matched by CVE ID, not by vendor name.