Diyhi
Diyhi BBS: vulnerabilidades y CVE
Diyhi BBS tiene 10 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-9461 | Baja (2.1) | 0.37% | — | 26 ago 2025 | A weakness has been identified in diyhi bbs up to 6.8. The impacted element is an unknown function of the file src/main/java/cms/web/action/filePackage/FilePackageManageAction.java of the component File Compression… |
| CVE-2025-6762 | Baja (2.1) | 0.43% | — | 27 jun 2025 | A vulnerability classified as critical has been found in diyhi bbs up to 6.8. This affects the function getUrl of the file /admin/login of the component HTTP Header Handler. The manipulation of the argument Host leads… |
| CVE-2025-6453 | Baja (2.1) | 0.44% | — | 22 jun 2025 | A vulnerability classified as critical has been found in diyhi bbs 6.8. Affected is the function Add of the file /src/main/java/cms/web/action/template/ForumManageAction.java of the component API. The manipulation of… |
| CVE-2021-43103 | Alta (7.2) | 1.6% | — | 28 mar 2022 | A File Upload vulnerability exists in bbs 5.3 is via ForumManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. |
| CVE-2021-43102 | Alta (7.2) | 1.6% | — | 28 mar 2022 | A File Upload vulnerability exists in bbs 5.3 is via HelpManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. |
| CVE-2021-43101 | Alta (7.2) | 1.6% | — | 28 mar 2022 | A File Upload vulnerability exists in bbs 5.3 is via MembershipCardManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. |
| CVE-2021-43100 | Alta (7.2) | 1.6% | — | 28 mar 2022 | A File Upload vulnerability exists in bbs 5.3 is via TopicManageAction.java in a GetType function, which lets a remote malicious user execute arbitrary code. |
| CVE-2021-43099 | Media (4.9) | 1.1% | — | 28 mar 2022 | An Archive Extraction (AKA "Zip Slip) vulnerability exists in bbs 5.3 in the UpgradeNow function in UpgradeManageAction.java, which unzips the arbitrary upladed zip file without checking filenames. The vulnerability is… |
| CVE-2021-43098 | Alta (7.2) | 1.2% | — | 28 mar 2022 | A File Upload vulnerability exists in bbs v5.3 via QuestionManageAction.java in a getType function. |
| CVE-2021-43097 | Alta (7.2) | 2.4% | — | 28 mar 2022 | A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code. |