Diyhi develops a focused line of bulletin-board and forum software that, despite a narrow product scope, occupies a position of interest within community and discussion platforms. The vendor's vulnerability profile centers on recurrent weaknesses in file handling and access control—including unrestricted file uploads, path traversal, information exposure, and code-injection flaws—that are characteristic of server-side forum engines managing user-supplied content and administrative boundaries. A meaningful share of disclosures reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Diyhi over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23390CRITICAL An issue in the getType function of BBS Forum v5.3 and below allows attackers to upload arbitrary files. | Feb 14, 2022 | 9.8 | 29 | NO | NO |
CVE-2025-9461HIGH A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java | Aug 26, 2025 | 7.5 | 25 | NO | NO |
CVE-2021-43097HIGH A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code. | Mar 28, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-43103HIGH A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | Mar 28, 2022 | 7.2 | 23 | NO | NO |
CVE-2021-43102HIGH A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | Mar 28, 2022 | 7.2 | 23 | NO | NO |
CVE-2021-43098HIGH A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. | Mar 28, 2022 | 7.2 | 23 | NO | NO |
CVE-2021-43101HIGH A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | Mar 28, 2022 | 7.2 | 22 | NO | NO |
CVE-2021-43100HIGH A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. | Mar 28, 2022 | 7.2 | 22 | NO | NO |
CVE-2025-6762HIGH A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the component HTTP Header Handler. The ma | Jun 27, 2025 | 7.2 | 20 | NO | NO |
CVE-2021-43099MEDIUM An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.java, which unzips the arbitrary upladed zip file without ch | Mar 28, 2022 | 4.9 | 18 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Diyhi.
Media articles that mention a CVE ID that affects a product developed by Diyhi — matched by CVE ID, not by vendor name.