📦 Hfly

by Baowzh

🔍 What is Hfly?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-14520

MEDIUM CVSS 5.4 Dec 11, 2025

This CVE describes a path traversal vulnerability in baowzh hfly's admin interface that allows remote attackers to delete arbitrary files by manipulating the filename parameter. The vulnerability affe...

CVE-2025-14521

MEDIUM CVSS 4.3 Dec 11, 2025

This CVE describes a path traversal vulnerability in baowzh hfly's admin interface that allows attackers to read arbitrary files on the server. The vulnerability exists in the /admin/index.php/datafil...

CVE-2025-14522

MEDIUM CVSS 6.3 Dec 11, 2025

This CVE describes an unrestricted file upload vulnerability in baowzh hfly's upload_json.php component. Attackers can remotely upload malicious files by manipulating the imgFile parameter, potentiall...

CVE-2025-14519

LOW CVSS 3.5 Dec 11, 2025

This CVE describes a stored cross-site scripting (XSS) vulnerability in the baowzh hfly travel website CMS. Attackers can inject malicious scripts into the advtext module's add functionality, which ar...