Feehi's vulnerability profile centers on a narrowly scoped content-management system platform that, despite modest product breadth, has drawn significant disclosure attention and ranks among the more prominent vendors in the landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, concentrating in the core Feehi CMS product through a durable pattern of web-application weakness classes including cross-site scripting, unrestricted file uploads, server-side request forgery, cross-site request forgery, and injection flaws. These recurring flaws reflect common attack vectors against web-facing CMS platforms where user input handling and file-management functionality present substantial risk surfaces. Defenders deploying this CMS should prioritize input sanitization, file-upload controls, and CSRF protections; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Feehi over time
Signals from CVEs in this vendor scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21516CRITICAL There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code. | Sep 6, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-21489CRITICAL File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-21174CRITICAL File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-34140MEDIUM A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload | Jul 28, 2022 | 5.4 | 30 | NO | YES |
CVE-2020-21322CRITICAL An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file. | Sep 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-8296CRITICAL A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8295CRITICAL A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbann | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8294CRITICAL A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The ma | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-34971HIGH An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file. | Jul 27, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-30108CRITICAL Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it. | May 24, 2021 | 9.1 | 27 | NO | NO |
Signals from CVEs in this vendor scope (36 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Feehi.
Media articles that mention a CVE ID that affects a product developed by Feehi — matched by CVE ID, not by vendor name.