CVE-2018-8717: Joyplus-CMS Project Joyplus-CMS
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
Affected products
- Joyplus-CMS Project Joyplus-CMS: version 1.6.0 only
Published 2018-03-15. Last modified 2026-06-17.