Fiyo Cms
Vendor:
First CVE: Jun 11, 2014 · Active for 12 years
26
Total CVEs
More Total CVEs than 96% of tracked products
5.2
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fiyo Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jun 11, 2014
12 years ago
Most Recent CVE
Jun 17, 2021
1,866 days ago
CVE Severity & Scoring
Fiyo Cms26 CVEs
19%
31%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (88.5%)
Unknown3 (11.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (88.5%)
High0 (0.0%)
Unknown3 (11.5%)
User Interaction
None20 (76.9%)
Unknown3 (11.5%)
Required3 (11.5%)
Privileges Required
Low2 (7.7%)
High0 (0.0%)
None21 (80.8%)
Unknown3 (11.5%)
Top CVEs
Signals from CVEs in this product scope (26 CVEs).
26 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6823HIGH Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action. | Mar 12, 2017 | 8.8 | 42 | NO | YES |
CVE-2014-9148CRITICAL Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view par | Oct 16, 2017 | 9.8 | 39 | NO | YES |
CVE-2015-3934CRITICAL Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating | Nov 21, 2017 | 9.8 | 35 | NO | YES |
CVE-2014-9147HIGH Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | Oct 16, 2017 | 7.5 | 33 | NO | YES |
CVE-2017-7625CRITICAL In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code. | Apr 10, 2017 | 9.8 | 32 | NO | NO |
CVE-2017-11419CRITICAL Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title']. | Jul 18, 2017 | 9.8 | 31 | NO | NO |
CVE-2017-11418CRITICAL Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i]. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-11417CRITICAL Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id']. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-11416CRITICAL Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
CVE-2017-11415CRITICAL Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level']. | Jul 18, 2017 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (26 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
23.1% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (26 CVEs).
Media Mentions
Signals from CVEs in this product scope (26 CVEs).
Top CNAs Publishing CVEs For Fiyo Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.0.7 | 18 | 8.8 | 1.2% | 0 | 0 |
| 2.0.6.1 | 2 | 7.5 | 4.4% | 0 | 1 |
| 2.0.6 | 1 | 9.8 | 3.2% | 0 | 0 |
| 2.0.2.1 | 1 | 9.8 | 3.2% | 0 | 0 |
| 2.0.1.9.1 | 1 | 9.8 | 3.1% | 0 | 1 |
| 2.0.1.8 | 3 | 7.2 | 2.6% | 0 | 2 |
| 2.0.1.6 | 1 | 9.8 | 3.2% | 0 | 0 |
| 2.0 | 1 | 9.8 | 3.2% | 0 | 0 |
| 1.5.7 | 1 | 4.3 | 1.8% | 0 | 0 |