Skip to main content

Vendor/product archive

qianfox / foxcms CVEs

Beta · best-effort

10 CVEs tagged to qianfox / foxcms1 Critical, 0 High, 6 Medium, 3 Low, 0 Unrated.

CVE-2025-11306

Published Oct 5, 2025

A vulnerability was found in qianfox FoxCMS up to 1.2. This affects an unknown part of the file /index.php/Search of the component Search Page. The manipulation of the argument ke…

CVSS 2.1 · Low
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2025-51650

Published Jul 14, 2025

An arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary code via uploading a crafted template fil…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-7568

Published Jul 14, 2025

A vulnerability was found in qianfox FoxCMS up to 1.2.5. It has been classified as critical. Affected is the function batchCope of the file app/admin/controller/Video.php. The man…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-6094

Published Jun 15, 2025

A vulnerability, which was classified as critical, has been found in qianfox FoxCMS up to 1.2.5. This issue affects the function batchCope of the file app/admin/controller/Downloa…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-45239

Published May 5, 2025

An issue in the restores method (DataBackup.php) of foxcms v2.0.6 allows attackers to execute a directory traversal.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-45238

Published May 5, 2025

foxcms v1.2.5 was discovered to contain an arbitrary file deletion vulnerability via the delRestoreSerie method.

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-45240

Published May 5, 2025

foxcms v1.2.5 was discovered to contain a SQL injection vulnerability via the executeCommand method in DataBackup.php.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-2653

Published Mar 23, 2025

A vulnerability was found in FoxCMS 1.25 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to improper authorization. The…

CVSS 5.3 · Medium
evidence mentions
4
Buzz score
22.6
Vendor/product tagsBeta · best-effort

CVE-2024-12901

Published Dec 23, 2024

A vulnerability classified as critical was found in FoxCMS up to 1.2. Affected by this vulnerability is an unknown functionality of the file /app/api/controller/Site.php of the co…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-12900

Published Dec 23, 2024

A vulnerability classified as critical has been found in FoxCMS up to 1.2. Affected is an unknown function of the file /install/installdb.php of the component Configuration File H…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1