VYPR

Qibocms X1

by Qibosoft

CVEs (2)

  • CVE-2025-22973HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.

  • CVE-2024-1225HigFeb 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file /application/index/controller/Pay.php. The manipulation of the argument callback_class leads to deserialization. The attack can…