CVE-2017-7625: Fiyo CMS

Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.

In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.

Affected products

  • Fiyo Fiyo CMS: version 2.0 only; version 2.0.1.6 only; version 2.0.1.8 only; version 2.0.2.1 only; version 2.0.6 only; version 2.0.7 only

Published 2017-04-10. Last modified 2026-06-17.