← Back

Hybbs2

hybbs2

Vendor: Hyphp • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hyphp
1Hybbs2
Jun 17, 2026
Feb 9, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.
1Hyphp
1Hybbs2
Jun 17, 2026
Feb 9, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.