CVE Tools

07fly

8 CVEs tracked since 2024. Since Oct 2024, none of them reached CISA KEV.

07fly CVEs per month

Oct 2024 to Jan 2025. Point at a month, or focus the strip and use the arrow keys.
07fly CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2024-1040
2024-11null or fewer
2024-12null or fewer
2025-0140

Products

The products that kept showing up in 07fly's monthly top three, with their CVEs summed over those months.

  1. 07flycms62 months
  2. Customer Relationship Management62 months

Latest CVEs

The 14 most recently published vulnerabilities affecting 07fly.

  1. CVE-2025-707807FLYCMS/07FLY-CMS/07FlyCRM cross-site request forgery4.3
  2. CVE-2025-25379Cross Site Request Forgery vulnerability in 07FLYCMS v.1.3.9 allows a remote attacker to execute arbitrary code via the id parameter of the del.html component.9.6
  3. CVE-2024-5761107FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via admin/doAdminAction.php?act=editShop&shopId.3.5
  4. CVE-2024-5716007FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.4.3
  5. CVE-2024-5715907FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/add.html.3.5
  6. CVE-2024-5716107FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html4.3
  7. CVE-2024-5115607FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component 'erp.07fly.net:80/admin/SysNotifyUser/del.html?id=93'.4.7
  8. CVE-2024-5115707FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component http://erp.07fly.net:80/oa/OaSchedule/add.html.4.7
  9. CVE-2024-990407FLYCMS/07FLY-CMS/07FlyCRM pictureUpload unrestricted upload4.7
  10. CVE-2024-990307FLYCMS/07FLY-CMS/07FlyCRM fileUpload unrestricted upload4.7
  11. CVE-2024-985607FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting2.4
  12. CVE-2024-985507FLYCMS/07FLY-CMS/07FlyCRM Module Plug-In sysmodule_1 uploadFile unrestricted upload4.7
  13. CVE-2023-502007FLY CRM Administrator Login Page sql injection7.3
  14. CVE-2023-305807FLY CRM User Profile cross site scripting3.5

The record

Peak rank
#167 in Oct 2024
Busiest month shown
Oct 2024, 4 CVEs
Months with a KEV entry
0 since Oct 2024
Monthly snapshots
2 since 2024
07fly's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store