VYPR
Vendor

Joyplus Project

Products
2
CVEs
4
Across products
4
Status
Private

Products

2

Recent CVEs

4
  • CVE-2019-16656CriSep 21, 2019
    risk 0.64cvss 9.8epss 0.01

    joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.

  • CVE-2018-14501CriJul 22, 2018
    risk 0.64cvss 9.8epss 0.01

    manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.

  • CVE-2019-16660HigSep 21, 2019
    risk 0.57cvss 8.8epss 0.01

    joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.

  • CVE-2019-16655HigSep 21, 2019
    risk 0.49cvss 7.5epss 0.01

    joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.