Feehi Cms
Vendor:
First CVE: Jan 26, 2021 · Active for 5 years
36
Total CVEs
More Total CVEs than 90% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 25% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Feehi Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2021
5 years ago
Most Recent CVE
Apr 6, 2026
109 days ago
CVE Severity & Scoring
Feehi Cms36 CVEs
69%
8%
22%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network36 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low36 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None13 (36.1%)
Unknown0 (0.0%)
Required23 (63.9%)
Privileges Required
Low14 (38.9%)
High2 (5.6%)
None20 (55.6%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (36 CVEs).
36 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-21516CRITICAL There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code. | Sep 6, 2022 | 9.8 | 31 | NO | NO |
CVE-2020-21489CRITICAL File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2020-21174CRITICAL File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function. | Jun 20, 2023 | 9.8 | 30 | NO | NO |
CVE-2022-34140MEDIUM A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload | Jul 28, 2022 | 5.4 | 30 | NO | YES |
CVE-2020-21322CRITICAL An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file. | Sep 15, 2021 | 9.8 | 30 | NO | NO |
CVE-2024-8296CRITICAL A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8295CRITICAL A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbann | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-8294CRITICAL A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The ma | Aug 29, 2024 | 9.8 | 27 | NO | NO |
CVE-2022-34971HIGH An arbitrary file upload vulnerability in the Advertising Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary code via a crafted PHP file. | Jul 27, 2022 | 8.8 | 27 | NO | NO |
CVE-2021-30108CRITICAL Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it. | May 24, 2021 | 9.1 | 27 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (36 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.8% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (36 CVEs).
Media Mentions
Signals from CVEs in this product scope (36 CVEs).
Top CNAs Publishing CVEs For Feehi Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.1.1 | 20 | 5.9 | 0.6% | 0 | 1 |
| 2.1.0 | 1 | 7.2 | 1.9% | 0 | 0 |
| 2.0.8 | 5 | 7.6 | 0.9% | 0 | 0 |
| 2.0.7.1 | 1 | 9.8 | 1.3% | 0 | 0 |
| 0.1.3 | 1 | 6.1 | 0.6% | 0 | 0 |