fiyo CVE Vulnerabilities & Metrics

Focus on fiyo vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About fiyo Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with fiyo. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total fiyo CVEs: 25
Earliest CVE date: 11 Jun 2014, 14:55 UTC
Latest CVE date: 17 Jun 2021, 16:15 UTC

Latest CVE reference: CVE-2020-35373

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical fiyo CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 6.49

Max CVSS: 7.8

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 0
4.0-6.9 11
7.0-8.9 15
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS fiyo CVEs

These are the five CVEs with the highest CVSS scores for fiyo, sorted by severity first and recency.

All CVEs for fiyo

CVE-2020-35373 fiyo vulnerability CVSS: 4.3 17 Jun 2021, 16:15 UTC

In Fiyo CMS 2.0.6.1, the 'tag' parameter results in an unauthenticated XSS attack.

CVE-2018-18545 fiyo vulnerability CVSS: 4.3 21 Oct 2018, 01:29 UTC

Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.

CVE-2017-17104 fiyo vulnerability CVSS: 7.8 04 Dec 2017, 08:29 UTC

Fiyo CMS 2.0.7 has an arbitrary file read vulnerability in dapur/apps/app_theme/libs/check_file.php via $_GET['src'] or $_GET['name'].

CVE-2017-17103 fiyo vulnerability CVSS: 6.5 04 Dec 2017, 08:29 UTC

Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.

CVE-2017-17102 fiyo vulnerability CVSS: 5.0 04 Dec 2017, 08:29 UTC

Fiyo CMS 2.0.7 has SQL injection in /system/site.php via $_REQUEST['link'].

CVE-2015-3934 fiyo vulnerability CVSS: 7.5 21 Nov 2017, 15:29 UTC

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0_1.9.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/app_article/controller/rating.php or (2) user parameter to user/login.

CVE-2014-9148 fiyo vulnerability CVSS: 7.5 16 Oct 2017, 15:29 UTC

Fiyo CMS 2.0.1.8 allows remote attackers to bypass intended access restrictions and execute the (1) "Install and Update" or (2) Backup super administrator function via the view parameter in a direct request to fiyo/dapur.

CVE-2014-9147 fiyo vulnerability CVSS: 5.0 16 Oct 2017, 15:29 UTC

Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.

CVE-2017-13778 fiyo vulnerability CVSS: 4.3 30 Aug 2017, 09:29 UTC

Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.

CVE-2017-11631 fiyo vulnerability CVSS: 7.5 26 Jul 2017, 08:29 UTC

dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.

CVE-2017-11630 fiyo vulnerability CVSS: 5.0 26 Jul 2017, 08:29 UTC

dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.

CVE-2017-11419 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].

CVE-2017-11418 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].

CVE-2017-11417 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].

CVE-2017-11416 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.

CVE-2017-11415 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level'].

CVE-2017-11414 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].

CVE-2017-11413 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id'].

CVE-2017-11412 fiyo vulnerability CVSS: 7.5 18 Jul 2017, 05:29 UTC

Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].

CVE-2017-11354 fiyo vulnerability CVSS: 7.5 17 Jul 2017, 13:18 UTC

Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.

CVE-2017-8853 fiyo vulnerability CVSS: 6.4 09 May 2017, 16:29 UTC

Fiyo CMS v2.0.7 has an arbitrary file delete vulnerability in dapur/apps/app_config/controller/backuper.php via directory traversal in the file parameter during an act=db action.

CVE-2017-7625 fiyo vulnerability CVSS: 7.5 10 Apr 2017, 17:59 UTC

In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.

CVE-2017-6823 fiyo vulnerability CVSS: 6.5 12 Mar 2017, 05:59 UTC

Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.

CVE-2014-9146 fiyo vulnerability CVSS: 4.3 14 Apr 2015, 14:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web script or HTML via the (1) view, (2) id, (3) page, or (4) app parameter to the default URI or the (5) act parameter to dapur/index.php.

CVE-2014-9145 fiyo vulnerability CVSS: 7.5 14 Apr 2015, 14:59 UTC

Multiple SQL injection vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an edit action to dapur/index.php; (2) cat, (3) user, or (4) level parameter to dapur/apps/app_article/controller/article_list.php; or (5) email parameter in an email action or (6) username parameter in a user action to dapur/apps/app_user/controller/check_user.php.

CVE-2014-4032 fiyo vulnerability CVSS: 4.3 11 Jun 2014, 14:55 UTC

Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the Nama field.