CVE-2022-40002
- EPSS 0.17%
- Veröffentlicht 15.12.2022 19:15:22
- Zuletzt bearbeitet 21.04.2025 16:15:50
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.
CVE-2022-40373
- EPSS 0.35%
- Veröffentlicht 15.12.2022 19:15:22
- Zuletzt bearbeitet 21.04.2025 15:15:51
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.
CVE-2022-40001
- EPSS 0.17%
- Veröffentlicht 15.12.2022 19:15:22
- Zuletzt bearbeitet 21.04.2025 16:15:50
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.
CVE-2022-40000
- EPSS 0.17%
- Veröffentlicht 15.12.2022 19:15:22
- Zuletzt bearbeitet 21.04.2025 16:15:50
Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.
CVE-2021-36573
- EPSS 0.21%
- Veröffentlicht 15.12.2022 19:15:15
- Zuletzt bearbeitet 21.04.2025 19:15:16
File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.
CVE-2021-36572
- EPSS 0.22%
- Veröffentlicht 15.12.2022 19:15:15
- Zuletzt bearbeitet 21.04.2025 19:15:16
Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page.
CVE-2020-36607
- EPSS 0.18%
- Veröffentlicht 15.12.2022 19:15:15
- Zuletzt bearbeitet 21.04.2025 20:15:17
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
CVE-2020-20589
- EPSS 0.28%
- Veröffentlicht 15.12.2022 19:15:15
- Zuletzt bearbeitet 21.04.2025 20:15:16
Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag.
CVE-2022-4014
- EPSS 0.14%
- Veröffentlicht 16.11.2022 08:15:28
- Zuletzt bearbeitet 21.11.2024 07:34:26
A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launc...
CVE-2022-43320
- EPSS 0.32%
- Veröffentlicht 09.11.2022 14:15:16
- Zuletzt bearbeitet 01.05.2025 16:15:25
FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer.