Known Vulnerabilities for products from Joyplus-cms Project
Listed below are 15 of the newest known vulnerabilities associated with the vendor "Joyplus-cms Project".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-22124 json | A vulnerability in the \inc\config.php component of joyplus-cms v1.6 allows attackers to access sensitive information. | 7.5 - HIGH | 2021-08-18 | 2021-08-24 |
| CVE-2020-20636 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-06-20 | 2023-06-27 |
| CVE-2019-17175 json | joyplus-cms 1.6.0 allows manager/admin_pic.php?rootpath= absolute path traversal. | 7.5 - HIGH | 2019-10-04 | 2019-10-08 |
| CVE-2018-14500 json | joyplus-cms 1.6.0 has XSS via the manager/collect/collect_vod_zhuiju.php keyword parameter. | 6.1 - MEDIUM | 2018-07-22 | 2020-02-18 |
| CVE-2018-14389 json | joyplus-cms 1.6.0 has SQL Injection via the manager/admin_ajax.php val parameter. | 9.8 - CRITICAL | 2018-07-18 | 2018-09-12 |
| CVE-2018-14388 json | joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter. | 5.4 - MEDIUM | 2018-07-18 | 2018-09-12 |
| CVE-2018-14334 json | manager/editor/upload.php in joyplus-cms 1.6.0 allows arbitrary file upload because detection of a prohibited file extension ... | 9.8 - CRITICAL | 2018-07-17 | 2018-09-17 |
| CVE-2018-12905 json | joyplus-cms 1.6.0 has XSS in admin_player.php, related to manager/index.php "system manage" and "add" actions. | 6.1 - MEDIUM | 2018-06-27 | 2018-08-20 |
| CVE-2018-12039 json | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary SQL command execution issue in manager/index.php invol... | 9.8 - CRITICAL | 2018-06-07 | 2018-07-27 |
| CVE-2018-10096 json | joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request. | 4.8 - MEDIUM | 2018-04-13 | 2018-05-11 |
| CVE-2018-10073 json | joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter. | 4.8 - MEDIUM | 2018-04-12 | 2018-05-14 |
| CVE-2018-10028 json | joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI. | 5.3 - MEDIUM | 2018-04-11 | 2018-05-11 |
| CVE-2018-8767 json | joyplus-cms 1.6.0 has XSS in manager/admin_ajax.php?action=save&tab={pre}vod_type via the t_name parameter. | 4.8 - MEDIUM | 2018-03-18 | 2018-04-13 |
| CVE-2018-8766 json | joyplus-cms 1.6.0 allows Remote Code Execution because of an Arbitrary File Upload issue in manager/editor/upload.php, relate... | 9.8 - CRITICAL | 2018-03-18 | 2018-04-13 |
| CVE-2018-8717 json | joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={... | 8.8 - HIGH | 2018-03-15 | 2018-04-09 |
Known software with vulnerabilities from Joyplus-cms Project
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Joyplus-cms Project | Joyplus-cms | 1.5 |