VYPR

Feehicms

by Feehi

Source repositories

CVEs (38)

  • CVE-2022-34140MedJul 28, 2022
    risk 0.38cvss 5.4epss 0.05

    A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.

  • CVE-2026-31313MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field.

  • CVE-2026-31354MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.

  • CVE-2026-31353MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

  • CVE-2026-31352MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Role Name parameter.

  • CVE-2026-31350MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Page Sign parameter.

  • CVE-2022-40373MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

  • CVE-2022-40002MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.

  • CVE-2022-40001MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.

  • CVE-2022-40000MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.

  • CVE-2021-36573MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.00

    File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.

  • CVE-2022-40408MedSep 29, 2022
    risk 0.35cvss 5.4epss 0.00

    FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.

  • CVE-2020-21146MedJan 26, 2021
    risk 0.33cvss 6.1epss 0.01

    Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.

  • CVE-2026-31351MedApr 6, 2026
    risk 0.31cvss 4.8epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

  • CVE-2025-63522MedDec 1, 2025
    risk 0.30cvss 4.6epss 0.00

    Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function

  • CVE-2022-4014MedNov 16, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier…

  • CVE-2026-51953HigJul 31, 2026
    risk 0.00cvss 7.4epss 0.00

    An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components

  • CVE-2026-13546HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.00

    A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been made…

Page 2 of 2