VYPR

Feehi CMS

by Liufee

Source repositories

CVEs (2)

  • CVE-2026-86239MedSep 7, 2026
    risk 0.34cvss 5.3epss 0.01

    A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulation leads to unrestricted upload. Remote exploitation of…

  • CVE-2026-86240MedSep 7, 2026
    risk 0.31cvss 4.7epss 0.00

    A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[] results in server-side request forgery. The attack can be…