Wdoyo's vulnerability footprint centers on its DoyoCMS and Doyo products, a modest content-management platform with a narrow product scope. The recurring exposure reflects classic web-application input-handling risks, centered on cross-site request forgery, cross-site scripting, and SQL injection—weakness classes endemic to web frameworks where user input flows to output rendering or database queries. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wdoyo over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-19821HIGH A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter. | Aug 26, 2021 | 8.8 | 28 | NO | NO |
CVE-2019-7569HIGH An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1 | Feb 7, 2019 | 8.8 | 22 | NO | NO |
CVE-2019-9551MEDIUM An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS. | Mar 4, 2019 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wdoyo.
Media articles that mention a CVE ID that affects a product developed by Wdoyo — matched by CVE ID, not by vendor name.