Hisiphp is a PHP-based content management and portal system whose vulnerability profile centers on server-side code injection, cross-site scripting, cross-site request forgery, and unsafe file upload handling—a set of weaknesses characteristic of web application frameworks where user input flows directly into code generation and rendering. Vulnerabilities affecting the vendor skew toward serious outcomes, and defenders should prioritize patching given the web-facing nature of typical deployments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hisiphp over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-33445CRITICAL An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component. | Apr 29, 2024 | 9.8 | 26 | NO | NO |
CVE-2018-17826HIGH HisiPHP 1.0.8 allows CSRF via admin.php/admin/user/adduser.html to add an administrator account. The attacker can then use that account to execute arbitrary PHP code by leveraging | Oct 1, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-28062HIGH An Access Control vulnerability exists in HisiPHP 2.0.11 via special packets that are constructed in $files = Dir::getList($decompath. '/ Upload/Plugins /, which could let a remote | Apr 4, 2022 | 7.2 | 25 | NO | NO |
CVE-2018-17827HIGH HisiPHP 1.0.8 allows remote attackers to execute arbitrary PHP code by editing a plugin's name to contain that code. This name is then injected into app/admin/model/AdminPlugins.ph | Oct 1, 2018 | 7.2 | 23 | NO | NO |
CVE-2019-1010193MEDIUM hisiphp 1.0.8 is affected by: Cross Site Scripting (XSS). | Jul 24, 2019 | 6.1 | 22 | NO | NO |
CVE-2020-21130MEDIUM Cross Site Scripting (XSS) vulnerability in HisiPHP 2.0.8 via the group name in addgroup.html. | Jun 21, 2021 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hisiphp.
Media articles that mention a CVE ID that affects a product developed by Hisiphp — matched by CVE ID, not by vendor name.