Fiyo operates a content management system that, despite a narrow product portfolio, ranks among the more prominent CMS platforms tracked in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the combination of web-facing exposure and the application-layer weakness classes that recur across its products. The exposure concentrates in Fiyo CMS and recurs through input-handling and authentication flaws including SQL injection, cross-site scripting, path traversal, information exposure, and authentication bypass by capture-replay—weaknesses characteristic of web applications with insufficient input validation and access controls. Defenders should treat Fiyo CMS instances as high-priority for patching and should restrict unauthenticated access where feasible, particularly to administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fiyo over time
Signals from CVEs in this vendor scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6823HIGH Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | Mar 12, 2017 | 8.8 | 42 | NO | YES |
CVE-2014-9148CRITICAL Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view par | Oct 16, 2017 | 9.8 | 39 | NO | YES |
CVE-2015-3934CRITICAL Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating | Nov 21, 2017 | 9.8 | 35 | NO | YES |
CVE-2014-9147HIGH Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | Oct 16, 2017 | 7.5 | 33 | NO | YES |
CVE-2017-7625CRITICAL In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code. | Apr 10, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-11419CRITICAL Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title']. | Jul 18, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-11418CRITICAL Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i]. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-11417CRITICAL Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id']. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-11416CRITICAL Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-11415CRITICAL Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level']. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (26 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fiyo.
Media articles that mention a CVE ID that affects a product developed by Fiyo — matched by CVE ID, not by vendor name.