Joyplus Cms
Vendor:
First CVE: Mar 15, 2018 · Active for 8 years
15
Total CVEs
More Total CVEs than 92% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Joyplus Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2018
8 years ago
Most Recent CVE
Jun 20, 2023
1,130 days ago
CVE Severity & Scoring
Joyplus Cms15 CVEs
47%
27%
27%
All CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low1 (6.7%)
High3 (20.0%)
None11 (73.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12905MEDIUM joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. | Jun 27, 2018 | 6.1 | 40 | NO | NO |
CVE-2018-12039CRITICAL joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a selec | Jun 7, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-8766CRITICAL joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add. | Mar 18, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-14389CRITICAL joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. | Jul 18, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-14334CRITICAL manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alt | Jul 17, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-8717HIGH joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request. | Mar 15, 2018 | 8.8 | 26 | NO | NO |
CVE-2020-22124HIGH A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. | Aug 18, 2021 | 7.5 | 24 | NO | NO |
CVE-2019-17175HIGH joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. | Oct 4, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-20636HIGH SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function. | Jun 20, 2023 | 7.5 | 23 | NO | NO |
CVE-2018-14500MEDIUM joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. | Jul 22, 2018 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (15 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (15 CVEs).
Media Mentions
Signals from CVEs in this product scope (15 CVEs).
Top CNAs Publishing CVEs For Joyplus Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.6.0 | 15 | 7.2 | 4.2% | 0 | 0 |