Joyplus CMS Project maintains a content management system with a modest but concentrated vulnerability footprint centered on its core Joyplus CMS product. The vendor is more prominent in the landscape than typical for its volume, suggesting focused adoption or deployment in specific environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joyplus Cms Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12905MEDIUM joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. | Jun 27, 2018 | 6.1 | 40 | NO | NO |
CVE-2018-12039CRITICAL joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a selec | Jun 7, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-8766CRITICAL joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add. | Mar 18, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-14389CRITICAL joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. | Jul 18, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14334CRITICAL manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alt | Jul 17, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-8717HIGH joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request. | Mar 15, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-22124HIGH A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. | Aug 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-17175HIGH joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. | Oct 4, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-20636HIGH SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function. | Jun 20, 2023 | 7.5 | 23 | NO | NO |
CVE-2018-14500MEDIUM joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. | Jul 22, 2018 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joyplus Cms Project.
Media articles that mention a CVE ID that affects a product developed by Joyplus Cms Project — matched by CVE ID, not by vendor name.