← Back

Feifeicms

feifeicms

6 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Feifeicms
feifeicms

CVEs (6)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Feifeicms
1Feifeicms
Nov 21, 2024
Jun 27, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A Cross site request forgery (CSRF) vulnerability was discovered in FeiFeiCMS v4.1.190209, which allows attackers to create administrator accounts via /index.php?s=Admin-Admin-Insert.
1Feifeicms
1Feifeicms
Nov 21, 2024
Mar 22, 2023
N/A· v4
5.4 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to...Show more
A vulnerability was found in FeiFeiCMS 2.7.130201. It has been classified as problematic. This affects an unknown part of the file \Public\system\slide_add.html of the component Extension Tool. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-223557 was assigned to this vulnerability.Show less
1Feifeicms
1Feifeicms
Nov 21, 2024
Apr 22, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to the " Admin/DataAction.class.php" component.
1Feifeicms
1Feifeicms
Nov 21, 2024
Apr 22, 2021
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Path Traversal in FeiFeiCMS v4.0 allows remote attackers to delete arbitrary files by sending a crafted HTTP request to " /index.php?s=/admin-tpl-del&id=".
1Feifeicms
1Feifeicms
Jun 17, 2026
Mar 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,g...Show more
FeiFeiCMS 4.1.190209 allows remote attackers to upload and execute arbitrary PHP code by visiting index.php?s=Admin-Index to modify the set of allowable file extensions, as demonstrated by adding php to the default jpg,gif,png,jpeg setting, and then using the "add article" feature.Show less
1Feifeicms
1Feifeicms
Jun 17, 2026
Feb 17, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
FeiFeiCms 4.0.181010 on Windows allows remote attackers to read or delete arbitrary files via index.php?s=Admin-Data-Down-id-..\ or index.php?s=Admin-Data-Del-id-..\ directory traversal.