Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Joyplus Cms Project

First CVE: Mar 15, 2018Active for: 8 yearsTotal CVEs: 30

Joyplus CMS Project maintains a content management system with a modest but concentrated vulnerability footprint centered on its core Joyplus CMS product. The vendor is more prominent in the landscape than typical for its volume, suggesting focused adoption or deployment in specific environments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
3.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Joyplus Cms Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2018
8 years ago
Most Recent CVE
Jun 20, 2023
1,130 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-12905MEDIUM
joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.
Jun 27, 20186.140NONO
CVE-2018-12039CRITICAL
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a selec
Jun 7, 20189.830NONO
CVE-2018-8766CRITICAL
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add.
Mar 18, 20189.830NONO
CVE-2018-14389CRITICAL
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
Jul 18, 20189.829NONO
CVE-2018-14334CRITICAL
manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alt
Jul 17, 20189.829NONO
CVE-2018-8717HIGH
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
Mar 15, 20188.826NONO
CVE-2020-22124HIGH
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
Aug 18, 20217.524NONO
CVE-2019-17175HIGH
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
Oct 4, 20197.524NONO
CVE-2020-20636HIGH
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
Jun 20, 20237.523NONO
CVE-2018-14500MEDIUM
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
Jul 22, 20186.120NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
47%
27%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low1 (6.7%)
High3 (20.0%)
None11 (73.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Joyplus Cms Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Joyplus Cms Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Joyplus Cms Project's Products

View all 1 CNAs →

Top CWEs