Vulnerabilities
9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-48116 | AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php. AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-47926 | AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php AyaCMS 3.1.2 is vulnerable to file deletion via /aya/module/admin/fst_del.inc.php NVD description · AI analysis pending | 9.8 group max | <1% | PoC |
| — | |
| CVE-2022-45550 | AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE). AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE). NVD description · AI analysis pending | 9.8 | 1% | PoC |
| — | |
| CVE-2022-45548 | AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. AyaCMS v3.1.2 has an Arbitrary File Upload vulnerability. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — | |
| CVE-2022-43074 | AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. AyaCMS v3.1.2 was discovered to contain an arbitrary file upload vulnerability via the component /admin/fst_upload.inc.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. NVD description · AI analysis pending | 9.8 | <1% | PoC |
| — | |
| CVE-2021-44238 | AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php, AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php, NVD description · AI analysis pending | 7.2 | 2% | PoC |
| — | |
| CVE-2020-23686 | Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts. Cross site request forgery (CSRF) vulnerability in AyaCMS 3.1.2 allows attackers to change an administrators password or other unspecified impacts. NVD description · AI analysis pending | 8.8 | <1% | PoC |
| — |