Hyphp develops the Hybbs product family, a web-based bulletin-board and community platform where the observed vulnerability surface centers on web-application input handling and file-upload controls. The recurring weakness classes—including cross-site request forgery, cross-site scripting, and unrestricted file uploads—reflect the classic attack surface of user-generated-content systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hyphp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-24677CRITICAL Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php. | Feb 9, 2022 | 9.8 | 30 | NO | NO |
CVE-2022-24676HIGH update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive. | Feb 9, 2022 | 8.8 | 27 | NO | NO |
CVE-2019-10644HIGH An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account. | Mar 30, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-14499MEDIUM An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html. | Mar 7, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hyphp.
Media articles that mention a CVE ID that affects a product developed by Hyphp — matched by CVE ID, not by vendor name.