VYPR

QiboCMS

by Qibosoft

CVEs (5)

  • CVE-2023-27037HigMar 16, 2023
    risk 0.57cvss 8.8epss 0.01

    Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php

  • CVE-2025-22973HigFeb 20, 2025
    risk 0.49cvss 7.5epss 0.00

    An issue in QiboSoft QiboCMS X1.0 allows a remote attacker to obtain sensitive information via the http_curl() function in the '/application/common. php' file that directly retrieves the URL request response content.

  • CVE-2024-1225HigFeb 5, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file /application/index/controller/Pay.php. The manipulation of the argument callback_class leads to deserialization. The attack can…

  • CVE-2020-18022MedApr 28, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the "ewebeditor\3.1.1\kindeditor.js" component.

  • CVE-2011-1064Feb 23, 2011
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aidDB[] parameter.