VYPR
Vendor

Feng Office

Products
2
CVEs
2
Across products
3
Status
Private

Products

2

Recent CVEs

2
  • CVE-2024-6039MedJun 16, 2024
    risk 0.44cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, was found in Feng Office 3.11.1.2. Affected is an unknown function of the component Workspaces. The manipulation of the argument dim leads to sql injection. It is possible to launch the attack remotely. The exploit has been…

  • CVE-2026-36669CriJul 17, 2026
    risk 0.00cvss 9.8epss 0.01

    An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious files (such as .html) to the web-accessible /tmp/ directory.