Feehi
Feehicms: vulnerabilidades y CVE
Feehicms tiene 28 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses9
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-86241 | Baja (2.1) | 0.49% | — | 7 sept 2026 | A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the… |
| CVE-2026-86240 | Baja (2) | 0.40% | — | 7 sept 2026 | A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument… |
| CVE-2026-86239 | Media (5.5) | 0.53% | — | 7 sept 2026 | A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The… |
| CVE-2026-51953 | Alta (7.4) | 0.45% | — | 31 jul 2026 | An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components |
| CVE-2025-15264 | Media (5.5) | 0.40% | — | 30 dic 2025 | A vulnerability was determined in FeehiCMS up to 2.1.1. Impacted is an unknown function of the file frontend/web/timthumb.php of the component TimThumb. Executing manipulation of the argument src can lead to server-side… |
| CVE-2025-65657 | Media (6.5) | 0.40% | — | 2 dic 2025 | FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticated remote attackers to upload files that the server later executes (or stores in… |
| CVE-2025-63523 | Media (6.5) | 0.26% | — | 1 dic 2025 | FeehiCMS version 2.1.1 fails to enforce server-side immutability for parameters that are presented to clients as "read-only." An authenticated attacker can intercept and modify the parameter in transit and the backend… |
| CVE-2025-63522 | Media (4.6) | 0.20% | — | 1 dic 2025 | Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function |
| CVE-2025-63520 | Media (6.1) | 0.24% | — | 1 dic 2025 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 via the id parameter of the User Update function (?r=user%2Fupdate). |
| CVE-2024-8296 | Media (5.3) | 0.76% | — | 29 ago 2024 | A vulnerability was found in FeehiCMS up to 2.1.1 and classified as critical. This issue affects the function insert of the file /admin/index.php?r=user%2Fcreate. The manipulation of the argument User[avatar] leads to… |
| CVE-2024-8295 | Media (5.3) | 0.76% | — | 29 ago 2024 | A vulnerability has been found in FeehiCMS up to 2.1.1 and classified as critical. This vulnerability affects the function createBanner of the file /admin/index.php?r=banner%2Fbanner-create. The manipulation of the… |
| CVE-2024-8294 | Media (5.3) | 0.76% | — | 29 ago 2024 | A vulnerability, which was classified as critical, was found in FeehiCMS up to 2.1.1. This affects the function update of the file /admin/index.php?r=friendly-link%2Fupdate. The manipulation of the argument… |
| CVE-2020-21489 | Crítica (9.8) | 1.3% | — | 20 jun 2023 | File Upload vulnerability in Feehicms v.2.0.8 allows a remote attacker to execute arbitrary code via the /admin/index.php?r=admin-user%2Fupdate-self component. |
| CVE-2020-21174 | Crítica (9.8) | 1.3% | — | 20 jun 2023 | File Upload vulenrability in liufee CMS v.2.0.7.1 allows a remote attacker to execute arbitrary code via the image suffix function. |
| CVE-2022-40373 | Media (5.4) | 0.51% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file. |
| CVE-2022-40002 | Media (5.4) | 0.51% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify. |
| CVE-2022-40001 | Media (5.4) | 0.51% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page. |
| CVE-2022-40000 | Media (5.4) | 0.51% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page. |
| CVE-2021-36573 | Media (5.4) | 0.47% | — | 15 dic 2022 | File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload. |
| CVE-2021-36572 | Media (6.1) | 0.43% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via the user name field of the login page. |
| CVE-2020-36607 | Media (6.1) | 0.65% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag. |
| CVE-2020-20589 | Media (6.1) | 0.59% | — | 15 dic 2022 | Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.0.8 allows remote attackers to run arbitrary code via tha lang attribute of an html tag. |
| CVE-2022-4014 | Media (4.3) | 0.21% | — | 16 nov 2022 | A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request… |
| CVE-2022-43320 | Media (6.1) | 0.43% | — | 9 nov 2022 | FeehiCMS v2.1.1 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the id parameter at /web/admin/index.php?r=log%2Fview-layer. |
| CVE-2022-40408 | Media (5.4) | 0.49% | — | 29 sept 2022 | FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module. |
| CVE-2020-21516 | Crítica (9.8) | 1.2% | — | 6 sept 2022 | There is an arbitrary file upload vulnerability in FeehiCMS 2.0.8 at the head image upload, that allows attackers to execute relevant PHP code. |
| CVE-2020-21322 | Crítica (9.8) | 1.8% | — | 15 sept 2021 | An arbitrary file upload vulnerability in Feehi CMS v2.0.8 and below allows attackers to execute arbitrary code via a crafted PHP file. |
| CVE-2020-19709 | Media (6.1) | 0.64% | — | 26 ago 2021 | Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.