Laobancms is a modestly represented content management system whose vulnerability disclosures concentrate in a single product and skew strongly toward critical-severity outcomes. The recurring weakness classes—cross-site scripting, path traversal, CSRF, sensitive information exposure, and code injection—reflect input-handling and access-control gaps endemic to web application platforms, particularly those managing financial or sensitive banking content. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Laobancms over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-19222CRITICAL An issue was discovered in LAOBANCMS 2.0. It allows a /install/mysql_hy.php?riqi=0&i=0 attack to reset the admin password, even if install.txt exists. | Nov 12, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-19328CRITICAL LAOBANCMS 2.0 allows install/mysql_hy.php?riqi=../ Directory Traversal. | Nov 17, 2018 | 9.8 | 30 | NO | NO |
CVE-2020-18166CRITICAL Unrestricted File Upload in LAOBANCMS v2.0 allows remote attackers to upload arbitrary files by attaching a file with a ".jpg.php" extension to the component "admin/wenjian.php?wj= | May 14, 2021 | 9.8 | 29 | NO | NO |
CVE-2018-19221CRITICAL An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter. | Nov 12, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-19220CRITICAL An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI. | Nov 12, 2018 | 9.8 | 29 | NO | NO |
CVE-2018-19225HIGH An issue was discovered in LAOBANCMS 2.0. admin/mima.php has CSRF. | Nov 12, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-19228HIGH An issue was discovered in LAOBANCMS 2.0. It allows arbitrary file deletion via ../ directory traversal in the admin/pic.php del parameter, as demonstrated by deleting install/inst | Nov 12, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-19224HIGH An issue was discovered in LAOBANCMS 2.0. /admin/login.php allows spoofing of the id and guanliyuan cookies. | Nov 12, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-19227MEDIUM An issue was discovered in LAOBANCMS 2.0. It allows XSS via the admin/liuyan.php neirong[] parameter. | Nov 12, 2018 | 5.4 | 20 | NO | NO |
CVE-2018-19226MEDIUM An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to list .txt files via a direct request for the /data/0/admin.txt URI. | Nov 12, 2018 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Laobancms.
Media articles that mention a CVE ID that affects a product developed by Laobancms — matched by CVE ID, not by vendor name.