← Back

Xiaohuanxiong Project

xiaohuanxiong_project

2 CVEs • 2 products

Products (2)

Click to collapse
Toggle

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xiaohuanxiong Project
1Xiaohuanxiong
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Xiaohuanxiong v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /app/controller/Books.php.
1Xiaohuanxiong Project
1Xiaohuanxiong Cms
Jun 17, 2026
Mar 23, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An issus was discovered in xiaohuanxiong CMS 5.0.17. There is a CSRF vulnerability that can modify administrator account's password.