Known Vulnerabilities for Joyplus-cms by Joyplus-cms Project
Listed below are 10 of the newest known vulnerabilities associated with "Joyplus-cms" by "Joyplus-cms Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-22124 json | A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. | 7.5 - HIGH | 2021-08-18 | 2021-08-24 |
| CVE-2020-20636 json | SQL injection vulnerability found in Joyplus-cms v.1.6.0 allows a remote attacker to access sensitive information via the id ... | 7.5 - HIGH | 2023-06-20 | 2023-06-27 |
| CVE-2019-17175 json | joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. | 7.5 - HIGH | 2019-10-04 | 2019-10-08 |
| CVE-2018-14500 json | joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. | 6.1 - MEDIUM | 2018-07-22 | 2020-02-18 |
| CVE-2018-14389 json | joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. | 9.8 - CRITICAL | 2018-07-18 | 2018-09-12 |
| CVE-2018-14388 json | joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter. | 5.4 - MEDIUM | 2018-07-18 | 2018-09-12 |
| CVE-2018-14334 json | manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension ... | 9.8 - CRITICAL | 2018-07-17 | 2018-09-17 |
| CVE-2018-12905 json | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. | 6.1 - MEDIUM | 2018-06-27 | 2018-08-20 |
| CVE-2018-12039 json | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php invol... | 9.8 - CRITICAL | 2018-06-07 | 2018-07-27 |
| CVE-2018-10096 json | joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. | 4.8 - MEDIUM | 2018-04-13 | 2018-05-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Joyplus-cms Project | Joyplus-cms | 1.6.0 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.9 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.8 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.7 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.6 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.5 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.4 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.3 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.2 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5.1 | |||
| Application | Joyplus-cms Project | Joyplus-cms | 1.5 |