Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Hisiphp

First CVE: Oct 1, 2018Active for: 8 yearsTotal CVEs: 6

Hisiphp is a PHP-based content management and portal system whose vulnerability profile centers on server-side code injection, cross-site scripting, cross-site request forgery, and unsafe file upload handling—a set of weaknesses characteristic of web application frameworks where user input flows directly into code generation and rendering. Vulnerabilities affecting the vendor skew toward serious outcomes, and defenders should prioritize patching given the web-facing nature of typical deployments. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.5
Avg CVSS Score
Higher Avg CVSS Score than 71% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Hisiphp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 1, 2018
7 years ago
Most Recent CVE
Apr 29, 2024
816 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-33445CRITICAL
An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.
Apr 29, 20249.826NONO
CVE-2018-17826HIGH
HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging
Oct 1, 20188.826NONO
CVE-2020-28062HIGH
An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote
Apr 4, 20227.225NONO
CVE-2018-17827HIGH
HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.ph
Oct 1, 20187.223NONO
CVE-2019-1010193MEDIUM
hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS).
Jul 24, 20196.122NONO
CVE-2020-21130MEDIUM
Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html.
Jun 21, 20216.121NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
50%
17%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (50.0%)
Unknown0 (0.0%)
Required3 (50.0%)
Privileges Required
Low0 (0.0%)
High2 (33.3%)
None4 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Hisiphp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Hisiphp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Hisiphp's Products

View all 2 CNAs →

Top CWEs