Doyocms Project maintains a web content management system where the observed vulnerability footprint centers on application-layer input handling and file management, with recurrent issues in unrestricted file uploads, cross-site request forgery, and SQL injection. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Doyocms Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19802CRITICAL File Upload vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the upload file type parameter. | Apr 11, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-26740CRITICAL Arbitrary file upload vulnerability sysupload.php in millken doyocms 2.3 allows attackers to execute arbitrary code. | Nov 1, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-26739CRITICAL SQL Injection vulnerability in pay.php in millken doyocms 2.3, allows attackers to execute arbitrary code, via the attribute parameter. | Nov 1, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-19803HIGH Cross Site Request Forgery vulnerability found in Milken DoyoCMS v.2.3 allows a remote attacker to execute arbitrary code via the background system settings. | Apr 11, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Doyocms Project.
Media articles that mention a CVE ID that affects a product developed by Doyocms Project — matched by CVE ID, not by vendor name.