Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Qibosoft

First CVE: Feb 23, 2011Active for: 15 yearsTotal CVEs: 14
29.1
VTI Score
Low

Qibosoft maintains a focused content-management system product line that, despite a narrow portfolio, ranks among the more prominent targets in the vulnerability landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across weakness classes including CSRF, cross-site scripting, code injection, SQL injection, and untrusted deserialization—reflecting the input-handling and code-execution risks endemic to web application frameworks. Defenders should prioritize patches for internet-facing deployments of Qibosoft's CMS products; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
0.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 5% of tracked vendors
7.6
Avg CVSS Score
Higher Avg CVSS Score than 72% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Qibosoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 23, 2011
15 years ago
Most Recent CVE
Feb 20, 2025
519 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-1225CRITICAL
A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file /application/index/controlle
Feb 5, 20249.830NONO
CVE-2019-17613CRITICAL
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alter
Oct 15, 20199.830NONO
CVE-2020-20944CRITICAL
An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.
Dec 27, 20219.129NONO
CVE-2020-20945HIGH
A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.
Dec 27, 20218.828NONO
CVE-2023-27037HIGH
Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php
Mar 16, 20238.827NONO
CVE-2018-18201HIGH
qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.
Oct 9, 20188.827NONO
CVE-2019-5725HIGH
qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the same web site to read a .sql fi
Jan 8, 20197.524NONO
CVE-2021-27811HIGH
A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edi
May 21, 20217.223NONO
CVE-2025-22973HIGH
An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retriev
Feb 20, 20257.522NONO
CVE-2011-1064MEDIUM
SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aidDB[] parameter.
Feb 23, 20116.821NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
36%
43%
21%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (92.9%)
Unknown1 (7.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High0 (0.0%)
Unknown1 (7.1%)
User Interaction
None7 (50.0%)
Unknown1 (7.1%)
Required6 (42.9%)
Privileges Required
Low2 (14.3%)
High1 (7.1%)
None10 (71.4%)
Unknown1 (7.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Qibosoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Qibosoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Qibosoft's Products

View all 2 CNAs →

Top CWEs