VYPR

cms

by Feehi CMS

CVEs (2)

  • CVE-2026-95264Oct 5, 2026
    risk 0.00cvss —epss —

    Feehi CMS 2.1.1 is vulnerable to Directory Traversal. An authenticated backend user with article edit permission can delete arbitrary files writable by the PHP process. Article image metadata is used to construct a filesystem path and is passed to `unlink()` without path…

  • CVE-2026-95263Oct 5, 2026
    risk 0.00cvss —epss —

    Feehi CMS 2.1.1 is vulnerable to Incorrect Access Control. A low-privilege backend administrator with administrator-update permission can change the password of the built-in super administrator account. The server does not enforce protection for this account, and the update…