fiyo security advisories
11 threat alerts tracking vulnerabilities and security advisories that affect fiyo products.
Vulnios monitors fiyo CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent fiyo security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2017-11631 — fiyo — fiyo_cms
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.
criticalCVE-2017-11631Critical Vulnerability: CVE-2017-11419 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in /apps/app_article/controller/editor.php via $_POST['id'] and $_POST['art_title'].
criticalCVE-2017-11419Critical Vulnerability: CVE-2017-11417 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_status.php via $_GET['id'].
criticalCVE-2017-11417Critical Vulnerability: CVE-2017-11413 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/comment_status.php via $_GET['id'].
criticalCVE-2017-11413Critical Vulnerability: CVE-2017-11415 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/sys_article.php via $_POST['parent_id'], $_POST['desc'], $_POST['keys'], and $_POST['level'].
criticalCVE-2017-11415Critical Vulnerability: CVE-2017-11416 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.
criticalCVE-2017-11416Critical Vulnerability: CVE-2017-11418 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_article/controller/article_list.php via $_GET['cat'], $_GET['user'], $_GET['level'], and $_GET['iSortCol_'.$i].
criticalCVE-2017-11418Critical Vulnerability: CVE-2017-11412 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/controller/comment_status.php via $_GET['id'].
criticalCVE-2017-11412Critical Vulnerability: CVE-2017-11414 — fiyo — fiyo_cms
Fiyo CMS 2.0.7 has SQL injection in dapur/apps/app_comment/sys_comment.php via $_POST['comment'], $_POST['name'], $_POST['web'], $_POST['email'], $_POST['status'], $_POST['id'], and $_REQUEST['id'].
criticalCVE-2017-11414Critical Vulnerability: CVE-2017-11354 — fiyo — fiyo_cms
Fiyo CMS v2.0.7 has an SQL injection vulnerability in dapur/apps/app_article/sys_article.php via the name parameter in editing or adding a tag name.
criticalCVE-2017-11354Critical Vulnerability: CVE-2017-7625 — fiyo — fiyo_cms
In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.
criticalCVE-2017-7625
Track fiyo exposure across your environment
Vulnios automatically cross-references your asset inventory against new fiyo CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan