Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Feehi

First CVE: Jan 26, 2021Active for: 5 yearsTotal CVEs: 36
33.2
VTI Score
Medium

Feehi's vulnerability profile centers on a narrowly scoped content-management system platform that, despite modest product breadth, has drawn significant disclosure attention and ranks among the more prominent vendors in the landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in the core Feehi CMS product through a durable pattern of web-application weakness classes including cross-site scripting, unrestricted file uploads, server-side request forgery, cross-site request forgery, and injection flaws. These recurring flaws reflect common attack vectors against web-facing CMS platforms where user input handling and file-management functionality present substantial risk surfaces. Defenders deploying this CMS should prioritize input sanitization, file-upload controls, and CSRF protections; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
36
Total CVEs
More Total CVEs than 98% of tracked vendors
3.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Feehi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2021
5 years ago
Most Recent CVE
Apr 6, 2026
109 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (36 CVEs).

36 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-21516CRITICAL
There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code.
Sep 6, 20229.831NONO
CVE-2020-21489CRITICAL
File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component.
Jun 20, 20239.830NONO
CVE-2020-21174CRITICAL
File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function.
Jun 20, 20239.830NONO
CVE-2022-34140MEDIUM
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload
Jul 28, 20225.430NOYES
CVE-2020-21322CRITICAL
An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file.
Sep 15, 20219.830NONO
CVE-2024-8296CRITICAL
A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation
Aug 29, 20249.827NONO
CVE-2024-8295CRITICAL
A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbann
Aug 29, 20249.827NONO
CVE-2024-8294CRITICAL
A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The ma
Aug 29, 20249.827NONO
CVE-2022-34971HIGH
An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file.
Jul 27, 20228.827NONO
CVE-2021-30108CRITICAL
Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.
May 24, 20219.127NONO
View all 36 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products36 CVEs
69%
8%
22%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (36.1%)
Unknown0 (0.0%)
Required23 (63.9%)
Privileges Required
Low14 (38.9%)
High2 (5.6%)
None20 (55.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (36 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Feehi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Feehi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Feehi's Products

View all 2 CNAs →

Top CWEs