Joyplus Cms

Vendor:

First CVE: Mar 15, 2018 · Active for 8 years

15
Total CVEs
More Total CVEs than 92% of tracked products
3.8
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Joyplus Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2018
8 years ago
Most Recent CVE
Jun 20, 2023
1,130 days ago

CVE Severity & Scoring

Joyplus Cms15 CVEs
All CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (53.3%)
Unknown0 (0.0%)
Required7 (46.7%)
Privileges Required
Low1 (6.7%)
High3 (20.0%)
None11 (73.3%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions.
Jun 27, 20186.140NONO
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php involving use of a "/!select/" substring in place of a selec
Jun 7, 20189.830NONO
joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, related to manager/admin_vod.php?action=add.
Mar 18, 20189.830NONO
joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter.
Jul 18, 20189.829NONO
manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension simply sets the $errm value, and does not otherwise alt
Jul 17, 20189.829NONO
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
Mar 15, 20188.826NONO
A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information.
Aug 18, 20217.524NONO
joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal.
Oct 4, 20197.524NONO
SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id parameter of the goodbad() function.
Jun 20, 20237.523NONO
joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter.
Jul 22, 20186.120NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Joyplus Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.6.0157.24.2%00