← Back

Wdoyo

wdoyo

3 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Doyocms
doyocms
Doyo
doyo

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wdoyo
1Doyocms
Jun 17, 2026
Aug 26, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A SQL injection vulnerability in admin.php of DOYOCMS 2.3 allows attackers to execute arbitrary SQL commands via the orders[] parameter.
1Wdoyo
1Doyocms
Jun 17, 2026
Mar 4, 2019
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in DOYO (aka doyocms) 2.3 through 2015-05-06. It has admin.php XSS.
1Wdoyo
1Doyo
Jun 17, 2026
Feb 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in DOYO (aka doyocms) 2.3(20140425 update). There is a CSRF vulnerability that can add a super administrator account via admin.php?c=a_adminuser&a=add&run=1.