PatchSiren

liufee CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW liufee CVE published 2026-09-07

CVE-2026-86241

A weakness in liufee FeehiCMS up to 2.1.1 allows remote attackers to manipulate the cookieValidationKey argument, potentially leading to use of a hard-coded cryptographic key. The vulnerability affects the Cookie Validation component, specifically in the environments/prod/backend/config/main-local.php file. Defenders should prioritize verifying the configuration of Cookie Validation in FeehiCMS and assess [truncated]

LOW liufee CVE published 2026-09-07

CVE-2026-86240

A security flaw has been discovered in liufee FeehiCMS up to 2.1.1, affecting the catchImage function of the UEditor component in the Uploader.php file. This vulnerability results in server-side request forgery, which can be executed remotely. Defenders responsible for FeehiCMS installations, particularly those using UEditor, should assess exposure and review server-side request forgery protections. The p [truncated]

MEDIUM liufee CVE published 2026-09-07

CVE-2026-86239

CVE-2026-86239 is a medium-severity vulnerability in liufee FeehiCMS up to 2.1.1, specifically in the UeditorAction::init function of the UEditor Widget, allowing for unrestricted file upload. This vulnerability has a CVSS score of 5.5 and is considered medium severity. The exploit is publicly available, but there is no information on widespread exploitation. Defenders should verify the presence of this v [truncated]