VYPR

CMS

by CAYIN Technology

CVEs (4)

  • CVE-2024-7729HigAug 14, 2024
    risk 0.49cvss 7.5epss 0.01

    The CAYIN Technology CMS lacks proper access control, allowing unauthenticated remote attackers to download arbitrary CGI files.

  • CVE-2026-80233HigAug 26, 2026
    risk 0.47cvss 7.2epss 0.01

    CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN Technology have an Arbitrary File Upload vulnerability. Privileged remote attackers can upload and execute web shells backdoors, thereby enabling arbitrary code execution on the server.

  • CVE-2024-7728HigAug 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with administrator privileges to inject OS commands into the specific parameter and execute them on the remote server.

  • CVE-2026-80234MedAug 26, 2026
    risk 0.34cvss 5.3epss 0.01

    CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain media file lists via specific functionality, resulting in partial information disclosure.