DIY CMS is a niche content-management platform with a narrow product footprint centered on its core CMS and blog offerings, despite occupying a more prominent position in the vulnerability landscape than its volume alone would suggest. The recorded disclosures reflect vulnerabilities affecting these focused products, with live severity, exploitation, and exposure counts shown alongside this summary.
The number and severity of CVEs published that impact products developed by Diy Cms over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-6519HIGH SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php. | Jan 24, 2013 | 7.5 | 32 | NO | YES |
CVE-2011-5140HIGH Multiple SQL injection vulnerabilities in the blog module 1.0 for DiY-CMS allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to (a) tags.php, (b) | Aug 31, 2012 | 7.5 | 32 | NO | YES |
CVE-2010-3206HIGH Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang parameter to modules/guestbook/bloc | Sep 3, 2010 | 7.5 | 32 | NO | YES |
CVE-2012-6518MEDIUM Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for requests that create a poll via | Jan 24, 2013 | 6.8 | 30 | NO | YES |
CVE-2012-6517MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) question parameter to in /modules/poll/ | Jan 24, 2013 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Diy Cms.
Media articles that mention a CVE ID that affects a product developed by Diy Cms — matched by CVE ID, not by vendor name.