Foecms is a content-management system where the observed vulnerability pattern centers on the product's web-facing input-handling attack surface, with recurrent findings in cross-site scripting and SQL injection. Treat this as a focused vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Foecms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-4850HIGH SQL injection vulnerability in index.php in FoeCMS allows remote attackers to execute arbitrary SQL commands via the i parameter. | Jul 10, 2014 | 7.5 | 19 | NO | NO |
CVE-2014-4851MEDIUM Open redirect vulnerability in msg.php in FoeCMS allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the r parameter. | Jul 10, 2014 | 5.8 | 17 | NO | NO |
CVE-2014-4849MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in msg.php in FoeCMS allow remote attackers to inject arbitrary web script or HTML via the (1) e or (2) r parameter. | Jul 10, 2014 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Foecms.
Media articles that mention a CVE ID that affects a product developed by Foecms — matched by CVE ID, not by vendor name.