Joyplus ProjectCVEs & Vulnerabilities
4 CVEs affecting Joyplus Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
4 CVEs→ All vendors
Most Affected Products
joyplus 3joyplus-cms 1
CVE-2019-16660HIGH
joyplus-cms 1.6.0 has admin_ajax.php?action=savexml&tab=vodplay CSRF.
21 Sep 2019
8.8
CVSS
CVE-2019-16656CRITICAL
joyplus-cms 1.6.0 allows remote attackers to execute arbitrary PHP code via /install by placing the code in the name of an object in the database.
21 Sep 2019
9.8
CVSS
CVE-2019-16655HIGH
joyplus-cms 1.6.0 allows reinstallation if the install/ URI remains available.
21 Sep 2019
7.5
CVSS
CVE-2018-14501CRITICAL
manager/admin_ajax.php in joyplus-cms 1.6.0 has SQL Injection, as demonstrated by crafted POST data beginning with an "m_id=1 AND SLEEP(5)" substring.
22 Jul 2018
9.8
CVSS
← PrevPage 1 / 1Next →