Joyplus Project maintains a content-management system with a niche footprint, with the durable signal centered on application-layer security weaknesses including cross-site request forgery and SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Joyplus Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16656CRITICAL joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database. | Sep 21, 2019 | 9.8 | 32 | NO | NO |
CVE-2018-14501CRITICAL manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring. | Jul 22, 2018 | 9.8 | 29 | NO | NO |
CVE-2019-16660HIGH joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF. | Sep 21, 2019 | 8.8 | 28 | NO | NO |
CVE-2019-16655HIGH joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available. | Sep 21, 2019 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Joyplus Project.
Media articles that mention a CVE ID that affects a product developed by Joyplus Project — matched by CVE ID, not by vendor name.