Known Vulnerabilities for products from Hyphp
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Hyphp".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2022-24677 json | Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to ... | 9.8 - CRITICAL | 2022-02-09 | 2022-02-11 |
| CVE-2022-24676 json | update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive. | 8.8 - HIGH | 2022-02-09 | 2022-02-11 |
| CVE-2019-10644 json | An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account. | 8.8 - HIGH | 2019-03-30 | 2019-04-01 |
| CVE-2018-14499 json | An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html. | 6.1 - MEDIUM | 2019-03-07 | 2019-03-08 |
Known software with vulnerabilities from Hyphp
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Hyphp | Hybbs | 2.2 |