VYPR

Feehicms

by Feehi

Source repositories

CVEs (39)

  • CVE-2020-19709MedAug 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Insufficient filtering of the tag parameters in feehicms 0.1.3 allows attackers to execute arbitrary web or HTML via a crafted payload.

  • CVE-2022-34140MedJul 28, 2022
    risk 0.38cvss 5.4epss 0.05

    A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username field.

  • CVE-2026-31313MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Content field.

  • CVE-2026-31354MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.

  • CVE-2026-31353MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the Category module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

  • CVE-2026-31352MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the Role Management module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Role Name parameter.

  • CVE-2026-31350MedApr 6, 2026
    risk 0.35cvss 5.4epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Page Sign parameter.

  • CVE-2022-40373MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS 2.1.1 allows remote attackers to run arbitrary code via upload of crafted XML file.

  • CVE-2022-40002MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbirtary code via the callback parameter to /cms/notify.

  • CVE-2022-40001MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the title field of the create article page.

  • CVE-2022-40000MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in FeehiCMS-2.1.1 allows remote attackers to run arbitrary code via the username field of the admin log in page.

  • CVE-2021-36573MedDec 15, 2022
    risk 0.35cvss 5.4epss 0.00

    File Upload vulnerability in Feehi CMS thru 2.1.1 allows attackers to run arbitrary code via crafted image upload.

  • CVE-2022-40408MedSep 29, 2022
    risk 0.35cvss 5.4epss 0.00

    FeehiCMS v2.1.1 was discovered to contain a cross-site scripting (XSS) vulnerability via a crafted payload injected into the Comment box under the Single Page module.

  • CVE-2020-21146MedJan 26, 2021
    risk 0.33cvss 6.1epss 0.01

    Feehi CMS 2.0.8 is affected by a cross-site scripting (XSS) vulnerability. When the user name is inserted as JavaScript code, browsing the post will trigger the XSS.

  • CVE-2026-31351MedApr 6, 2026
    risk 0.31cvss 4.8epss 0.00

    An authenticated stored cross-site scripting (XSS) vulnerability in the creation/editing module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Title parameter.

  • CVE-2025-63522MedDec 1, 2025
    risk 0.30cvss 4.6epss 0.00

    Reverse Tabnabbing vulnerability in FeehiCMS 2.1.1 in the Comments Management function

  • CVE-2026-86241MedSep 7, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the argument cookieValidationKey causes use of hard-coded…

  • CVE-2022-4014MedNov 16, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, has been found in FeehiCMS. Affected by this issue is some unknown functionality of the component Post My Comment Tab. The manipulation leads to cross-site request forgery. The attack may be launched remotely. The identifier…

  • CVE-2026-13546HigJun 29, 2026
    risk 0.00cvss 7.3epss 0.01

    A vulnerability was found in Feehi CMS up to 2.1.1. This vulnerability affects unknown code of the file /api/articles of the component REST API Endpoint. Performing a manipulation results in missing authentication. The attack may be initiated remotely. The exploit has been made…

Page 2 of 2