finecms_project CVE Vulnerabilities & Metrics

Focus on finecms_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About finecms_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with finecms_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total finecms_project CVEs: 21
Earliest CVE date: 07 Mar 2017, 19:59 UTC
Latest CVE date: 09 Jan 2018, 21:29 UTC

Latest CVE reference: CVE-2017-1000429

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical finecms_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.86

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 1
4.0-6.9 17
7.0-8.9 3
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS finecms_project CVEs

These are the five CVEs with the highest CVSS scores for finecms_project, sorted by severity first and recency.

All CVEs for finecms_project

CVE-2017-1000429 finecms_project vulnerability CVSS: 4.3 09 Jan 2018, 21:29 UTC

rui Li finecms 5.0.10 is vulnerable to a reflected XSS in the file Weixin.php.

CVE-2017-14195 finecms_project vulnerability CVSS: 4.3 07 Sep 2017, 17:29 UTC

The call_msg function in controllers/Form.php in dayrui FineCms 5.0.11 might have XSS related to the Referer HTTP header with Internet Explorer.

CVE-2017-14194 finecms_project vulnerability CVSS: 4.3 07 Sep 2017, 17:29 UTC

The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer.

CVE-2017-14193 finecms_project vulnerability CVSS: 4.3 07 Sep 2017, 17:29 UTC

The oauth function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer.

CVE-2017-14192 finecms_project vulnerability CVSS: 4.3 07 Sep 2017, 17:29 UTC

The checktitle function in controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the module field.

CVE-2017-13697 finecms_project vulnerability CVSS: 4.3 25 Aug 2017, 17:29 UTC

controllers/member/api.php in dayrui FineCms 5.0.11 has XSS related to the dirname variable.

CVE-2017-12774 finecms_project vulnerability CVSS: 7.5 09 Aug 2017, 21:29 UTC

finecms in 1.9.5\controllers\member\ContentController.php allows remote attackers to operate website database

CVE-2017-11202 finecms_project vulnerability CVSS: 4.3 13 Jul 2017, 01:29 UTC

FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017-11180.

CVE-2017-11201 finecms_project vulnerability CVSS: 3.5 13 Jul 2017, 01:29 UTC

application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.

CVE-2017-11200 finecms_project vulnerability CVSS: 6.5 13 Jul 2017, 01:29 UTC

SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.

CVE-2017-11198 finecms_project vulnerability CVSS: 4.3 13 Jul 2017, 01:29 UTC

Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter.

CVE-2017-11167 finecms_project vulnerability CVSS: 7.5 12 Jul 2017, 13:29 UTC

FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value.

CVE-2017-11180 finecms_project vulnerability CVSS: 4.3 12 Jul 2017, 00:29 UTC

FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen.

CVE-2017-11179 finecms_project vulnerability CVSS: 4.3 12 Jul 2017, 00:29 UTC

FineCMS through 2017-07-11 has stored XSS in route=admin when modifying user information, and in route=register when registering a user account.

CVE-2017-11178 finecms_project vulnerability CVSS: 5.0 12 Jul 2017, 00:29 UTC

In FineCMS through 2017-07-11, application/core/controller/style.php allows remote attackers to write to arbitrary files via the contents and filename parameters in a route=style action. For example, this can be used to overwrite a .php file because the file extension is not checked.

CVE-2017-10968 finecms_project vulnerability CVSS: 7.5 07 Jul 2017, 11:29 UTC

In FineCMS through 2017-07-07, application\core\controller\template.php allows remote PHP code execution by placing the code after "<?php" in a route=template request.

CVE-2017-10973 finecms_project vulnerability CVSS: 4.3 06 Jul 2017, 16:29 UTC

In FineCMS before 2017-07-06, application/lib/ajax/get_image_data.php has SSRF, related to requests for non-image files with a modified HTTP Host header.

CVE-2017-10967 finecms_project vulnerability CVSS: 4.3 06 Jul 2017, 16:29 UTC

In FineCMS before 2017-07-06, application\core\controller\config.php allows XSS in the (1) key_name, (2) key_value, and (3) meaning parameters.

CVE-2017-9252 finecms_project vulnerability CVSS: 4.3 28 May 2017, 20:29 UTC

andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action.

CVE-2017-9251 finecms_project vulnerability CVSS: 4.3 28 May 2017, 20:29 UTC

andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the sitename parameter to admin.php.

CVE-2017-6511 finecms_project vulnerability CVSS: 4.3 07 Mar 2017, 19:59 UTC

andrzuk/FineCMS before 2017-03-06 is vulnerable to a reflected XSS in index.php because of missing validation of the action parameter in application/classes/application.php.