Fiyo
19 CVEs tracked since 2014. Since Jun 2014, none of them reached CISA KEV.
Fiyo CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2014-06 | 1 | 0 |
| 2014-07 | null or fewer | |
| 2014-08 | null or fewer | |
| 2014-09 | null or fewer | |
| 2014-10 | null or fewer | |
| 2014-11 | null or fewer | |
| 2014-12 | null or fewer | |
| 2015-01 | null or fewer | |
| 2015-02 | null or fewer | |
| 2015-03 | null or fewer | |
| 2015-04 | 2 | 0 |
| 2015-05 | null or fewer | |
| 2015-06 | null or fewer | |
| 2015-07 | null or fewer | |
| 2015-08 | null or fewer | |
| 2015-09 | null or fewer | |
| 2015-10 | null or fewer | |
| 2015-11 | null or fewer | |
| 2015-12 | null or fewer | |
| 2016-01 | null or fewer | |
| 2016-02 | null or fewer | |
| 2016-03 | null or fewer | |
| 2016-04 | null or fewer | |
| 2016-05 | null or fewer | |
| 2016-06 | null or fewer | |
| 2016-07 | null or fewer | |
| 2016-08 | null or fewer | |
| 2016-09 | null or fewer | |
| 2016-10 | null or fewer | |
| 2016-11 | null or fewer | |
| 2016-12 | null or fewer | |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | null or fewer | |
| 2017-04 | null or fewer | |
| 2017-05 | null or fewer | |
| 2017-06 | null or fewer | |
| 2017-07 | 11 | 0 |
| 2017-08 | null or fewer | |
| 2017-09 | null or fewer | |
| 2017-10 | 2 | 0 |
| 2017-11 | null or fewer | |
| 2017-12 | 3 | 0 |
Products
The products that kept showing up in Fiyo's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Fiyo.
- CVE-2020-35373In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.6.1
- CVE-2018-18545Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.6.1
- CVE-2017-17102Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].7.5
- CVE-2017-17103Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.8.8
- CVE-2017-17104Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].7.5
- CVE-2015-3934Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user ...9.8
- CVE-2014-9148Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direc...9.8
- CVE-2014-9147Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.7.5
- CVE-2017-13778Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.6.1
- CVE-2017-11630dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request,...7.5
- CVE-2017-11631dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.9.8
- CVE-2017-11418Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].9.8
- CVE-2017-11414Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].9.8
- CVE-2017-11412Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].9.8
- CVE-2017-11416Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.9.8
The record
- Peak rank
- #30 in Jul 2017
- Busiest month shown
- Jul 2017, 11 CVEs
- Months with a KEV entry
- 0 since Jun 2014
- Monthly snapshots
- 5 since 2014