Qianfox develops the FoxCMS content management system, a modestly represented platform in the vulnerability landscape. The recurring vulnerabilities affecting this product skew toward serious outcomes and cluster around injection-family weaknesses—including SQL injection, code injection, and path traversal—alongside improper authorization controls, reflecting common parsing and access-validation challenges in web-facing CMS implementations. Current severity and exploitation metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qianfox over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-12900CRITICAL A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File Ha | Dec 23, 2024 | 9.8 | 27 | NO | NO |
CVE-2025-45238CRITICAL foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method. | May 5, 2025 | 9.1 | 25 | NO | NO |
CVE-2025-7568HIGH A vulnerability was found in qianfox FoxCMS up to 1.2.5. It has been classified as critical. Affected is the function batchCope of the file app/admin/controller/Video.php. The mani | Jul 14, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-6094HIGH A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admin/controller/Download | Jun 15, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-11306MEDIUM A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The manipulation of the argument key | Oct 5, 2025 | 6.1 | 22 | NO | NO |
CVE-2025-45240MEDIUM foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php. | May 5, 2025 | 6.5 | 19 | NO | NO |
CVE-2025-51650MEDIUM An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template file | Jul 14, 2025 | 5.6 | 17 | NO | NO |
CVE-2024-12901MEDIUM A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the com | Dec 23, 2024 | 5.3 | 17 | NO | NO |
CVE-2025-45239MEDIUM An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal. | May 5, 2025 | 5.3 | 15 | NO | NO |
CVE-2025-2653MEDIUM A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The | Mar 23, 2025 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qianfox.
Media articles that mention a CVE ID that affects a product developed by Qianfox — matched by CVE ID, not by vendor name.