Laiketui is a modestly represented vendor whose vulnerabilities concentrate in a single product that appears to target web application and content management use cases. The vendor's disclosures skew strongly toward critical-severity outcomes and recur across application-layer input handling and file-upload weaknesses, including SQL injection, path traversal, unrestricted file uploads, and cross-site request forgery, which are characteristic of web frameworks with insufficient input validation and access control. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laiketui over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-40954CRITICAL Laiketui 3.5.0 is affected by an arbitrary file upload vulnerability that can allow an attacker to execute arbitrary code. | Jun 23, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-19159HIGH Cross Site Request Forgery (CSRF) in LaikeTui v3 allows remote attackers to execute arbitrary code via the component '/index.php?module=member&action=add'. | Sep 15, 2021 | 8.8 | 28 | NO | NO |
CVE-2023-4559CRITICAL A vulnerability, which was classified as critical, has been found in Bettershop LaikeTui. Affected by this issue is some unknown functionality of the file index.php?module=api&acti | Aug 27, 2023 | 9.8 | 27 | NO | NO |
CVE-2023-4988CRITICAL A vulnerability, which was classified as problematic, was found in Bettershop LaikeTui. This affects an unknown part of the file index.php?module=system&action=uploadImg. The manip | Sep 15, 2023 | 9.8 | 26 | NO | NO |
CVE-2021-34128HIGH LaikeTui 3.5.0 allows remote authenticated users to execute arbitrary PHP code by using index.php?module=system&action=pay to upload a ZIP archive containing a .php file, as demons | Jun 15, 2021 | 8.8 | 26 | NO | NO |
CVE-2021-40956HIGH LaiKetui v3.5.0 has SQL injection in the background through the menu management function, and sensitive data can be obtained. | Jun 23, 2022 | 7.5 | 24 | NO | NO |
CVE-2021-40955HIGH SQL injection exists in LaiKetui v3.5.0 the background administrator list. | Jun 23, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-34129HIGH LaikeTui 3.5.0 allows remote authenticated users to delete arbitrary files, as demonstrated by deleting install.lock in order to reinstall the product in an attacker-controlled man | Jun 15, 2021 | 8.1 | 24 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laiketui.
Media articles that mention a CVE ID that affects a product developed by Laiketui — matched by CVE ID, not by vendor name.