Hsycms is a web content management system with a compact vulnerability footprint centered on its core product, where the persistent signal reflects common application-layer input-handling deficiencies. The recurring weakness classes—cross-site scripting and SQL injection—are characteristic of CMS platforms and arise from insufficient neutralization of user-supplied data during page generation and database query construction. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hsycms over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10653CRITICAL An issue was discovered in Hsycms V1.1. There is a SQL injection vulnerability via a /news/*.html page. | Jul 10, 2019 | 9.8 | 27 | NO | NO |
CVE-2023-1349MEDIUM A vulnerability, which was classified as problematic, has been found in Hsycms 3.1. Affected by this issue is some unknown functionality of the file controller\cate.php of the comp | Mar 11, 2023 | 6.1 | 21 | NO | NO |
CVE-2019-9145MEDIUM An issue was discovered in Hsycms V1.1. There is an XSS vulnerability via the name field to the /book page. | Feb 25, 2019 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hsycms.
Media articles that mention a CVE ID that affects a product developed by Hsycms — matched by CVE ID, not by vendor name.