HyphpCVEs & Vulnerabilities
4 CVEs affecting Hyphp products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
hybbs 2hybbs2 2
CVE-2022-24677CRITICAL
Admin.php in HYBBS2 through 2.3.2 allows remote code execution because it writes plugin-related configuration information to conf.php.
9 Feb 2022
9.8
CVSS
CVE-2022-24676HIGH
update_code in Admin.php in HYBBS2 through 2.3.2 allows arbitrary file upload via a crafted ZIP archive.
9 Feb 2022
8.8
CVSS
CVE-2019-10644HIGH
An issue was discovered in HYBBS 2.2. /?admin/user.html has a CSRF vulnerability that can add an administrator account.
30 Mar 2019
8.8
CVSS
CVE-2018-14499MEDIUM
An issue was found in HYBBS through 2016-03-08. There is an XSS vulnerablity via an article title to post.html.
8 Mar 2019
6.1
CVSS
← PrevPage 1 / 1Next →