qibosoft CVE Vulnerabilities & Metrics

Focus on qibosoft vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About qibosoft Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with qibosoft. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total qibosoft CVEs: 12
Earliest CVE date: 23 Feb 2011, 01:00 UTC
Latest CVE date: 05 Feb 2024, 13:15 UTC

Latest CVE reference: CVE-2024-1225

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical qibosoft CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 5.03

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 3
4.0-6.9 8
7.0-8.9 2
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS qibosoft CVEs

These are the five CVEs with the highest CVSS scores for qibosoft, sorted by severity first and recency.

All CVEs for qibosoft

CVE-2024-1225 qibosoft vulnerability CVSS: 7.5 05 Feb 2024, 13:15 UTC

A vulnerability classified as critical was found in QiboSoft QiboCMS X1 up to 1.0.6. Affected by this vulnerability is the function rmb_pay of the file /application/index/controller/Pay.php. The manipulation of the argument callback_class leads to deserialization. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252847. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2020-20808 qibosoft vulnerability CVSS: 0 03 Aug 2023, 02:15 UTC

Cross Site Scripting vulnerability in Qibosoft qibosoft v.7 and before allows a remote attacker to execute arbitrary code via the eindtijd and starttijd parameters of do/search.php.

CVE-2023-27037 qibosoft vulnerability CVSS: 0 16 Mar 2023, 15:15 UTC

Qibosoft QiboCMS v7 was discovered to contain a remote code execution (RCE) vulnerability via the Get_Title function at label_set_rs.php

CVE-2020-20946 qibosoft vulnerability CVSS: 3.5 27 Dec 2021, 21:15 UTC

Qibosoft v7 contains a stored cross-site scripting (XSS) vulnerability in the component /admin/index.php?lfj=friendlink&action=add.

CVE-2020-20945 qibosoft vulnerability CVSS: 6.8 27 Dec 2021, 21:15 UTC

A Cross-Site Request Forgery (CSRF) in /admin/index.php?lfj=member&action=editmember of Qibosoft v7 allows attackers to arbitrarily add administrator accounts.

CVE-2020-20944 qibosoft vulnerability CVSS: 6.4 27 Dec 2021, 21:15 UTC

An issue in /admin/index.php?lfj=mysql&action=del of Qibosoft v7 allows attackers to arbitrarily delete files.

CVE-2020-20943 qibosoft vulnerability CVSS: 4.3 27 Dec 2021, 21:15 UTC

A Cross-Site Request Forgery (CSRF) in /member/post.php?job=postnew&step=post of Qibosoft v7 allows attackers to force victim users into arbitrarily publishing new articles via a crafted URL.

CVE-2021-27811 qibosoft vulnerability CVSS: 6.5 21 May 2021, 18:15 UTC

A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.

CVE-2020-18022 qibosoft vulnerability CVSS: 4.3 28 Apr 2021, 16:15 UTC

Cross Site Scripting (XSS) in Qibosoft QiboCMS v7 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information by injecting arbitrary commands in a HTTP request to the "ewebeditor\3.1.1\kindeditor.js" component.

CVE-2019-17613 qibosoft vulnerability CVSS: 7.5 15 Oct 2019, 23:15 UTC

qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.

CVE-2019-5725 qibosoft vulnerability CVSS: 5.0 08 Jan 2019, 23:29 UTC

qibosoft through V7 allows remote attackers to read arbitrary files via the member/index.php main parameter, as demonstrated by SSRF to a URL on the same web site to read a .sql file.

CVE-2018-18201 qibosoft vulnerability CVSS: 6.8 09 Oct 2018, 23:29 UTC

qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.

CVE-2011-1064 qibosoft vulnerability CVSS: 6.8 23 Feb 2011, 01:00 UTC

SQL injection vulnerability in member/list.php in qibosoft Qi Bo CMS 7 allows remote attackers to execute arbitrary SQL commands via the aidDB[] parameter.