Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fiyo

First CVE: Jun 11, 2014Active for: 12 yearsTotal CVEs: 26
66.1
VTI Score
TOP TARGET

Fiyo operates a content management system that, despite a narrow product portfolio, ranks among the more prominent CMS platforms tracked in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the combination of web-facing exposure and the application-layer weakness classes that recur across its products. The exposure concentrates in Fiyo CMS and recurs through input-handling and authentication flaws including SQL injection, cross-site scripting, path traversal, information exposure, and authentication bypass by capture-replay—weaknesses characteristic of web applications with insufficient input validation and access controls. Defenders should treat Fiyo CMS instances as high-priority for patching and should restrict unauthenticated access where feasible, particularly to administrative interfaces; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
26
Total CVEs
More Total CVEs than 97% of tracked vendors
5.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
8.3
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fiyo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2014
12 years ago
Most Recent CVE
Jun 17, 2021
1,863 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (26 CVEs).

26 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-6823HIGH
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.
Mar 12, 20178.842NOYES
CVE-2014-9148CRITICAL
Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view par
Oct 16, 20179.839NOYES
CVE-2015-3934CRITICAL
Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating
Nov 21, 20179.835NOYES
CVE-2014-9147HIGH
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.
Oct 16, 20177.533NOYES
CVE-2017-7625CRITICAL
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
Apr 10, 20179.832NONO
CVE-2017-11419CRITICAL
Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].
Jul 18, 20179.831NONO
CVE-2017-11418CRITICAL
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].
Jul 18, 20179.829NONO
CVE-2017-11417CRITICAL
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].
Jul 18, 20179.829NONO
CVE-2017-11416CRITICAL
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
Jul 18, 20179.829NONO
CVE-2017-11415CRITICAL
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level'].
Jul 18, 20179.829NONO
View all 26 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products26 CVEs
19%
31%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (88.5%)
Unknown3 (11.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (88.5%)
High0 (0.0%)
Unknown3 (11.5%)
User Interaction
None20 (76.9%)
Unknown3 (11.5%)
Required3 (11.5%)
Privileges Required
Low2 (7.7%)
High0 (0.0%)
None21 (80.8%)
Unknown3 (11.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (26 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
23.1% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fiyo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fiyo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fiyo's Products

View all 1 CNAs →

Top CWEs