CVE Tools

Fiyo

19 CVEs tracked since 2014. Since Jun 2014, none of them reached CISA KEV.

Fiyo CVEs per month

Jun 2014 to Dec 2017. Point at a month, or focus the strip and use the arrow keys.
Fiyo CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2014-0610
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-0420
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-02null or fewer
2016-03null or fewer
2016-04null or fewer
2016-05null or fewer
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-07110
2017-08null or fewer
2017-09null or fewer
2017-1020
2017-11null or fewer
2017-1230

Products

The products that kept showing up in Fiyo's monthly top three, with their CVEs summed over those months.

  1. Fiyo CMS195 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Fiyo.

  1. CVE-2020-35373In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.6.1
  2. CVE-2018-18545Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.6.1
  3. CVE-2017-17102Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].7.5
  4. CVE-2017-17103Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.8.8
  5. CVE-2017-17104Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].7.5
  6. CVE-2015-3934Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user ...9.8
  7. CVE-2014-9148Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direc...9.8
  8. CVE-2014-9147Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.7.5
  9. CVE-2017-13778Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.6.1
  10. CVE-2017-11630dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request,...7.5
  11. CVE-2017-11631dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.9.8
  12. CVE-2017-11418Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].9.8
  13. CVE-2017-11414Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].9.8
  14. CVE-2017-11412Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].9.8
  15. CVE-2017-11416Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.9.8

The record

Peak rank
#30 in Jul 2017
Busiest month shown
Jul 2017, 11 CVEs
Months with a KEV entry
0 since Jun 2014
Monthly snapshots
5 since 2014
Fiyo's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store