VYPR

CMS

by Feehi

CVEs (3)

  • CVE-2021-30108CriMay 24, 2021
    risk 0.52cvss 9.1epss 0.01

    Feehi CMS 2.1.1 is affected by a Server-side request forgery (SSRF) vulnerability. When the user modifies the HTTP Referer header to any url, the server can make a request to it.

  • CVE-2022-38796MedSep 14, 2022
    risk 0.40cvss 6.1epss 0.01

    A Host Header Injection vulnerability in Feehi CMS 2.1.1 may allow an attacker to spoof a particular header. This can be exploited by abusing password reset emails.

  • CVE-2022-34140MedJul 28, 2022
    risk 0.38cvss 5.4epss 0.05

    A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.