coolforum CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

coolforum vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to coolforum, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2006-2867 SQL injection vulnerability in editpost.php in CoolForum 0.8.3 beta and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. [email protected] 7.5 1.07% 2006-06-06 2026-04-16
CVE-2005-0858 Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the login parameter to register.php. [email protected] 7.5 0.33% 2005-05-02 2026-04-16
CVE-2005-0857 Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter. [email protected] 4.3 0.40% 2005-05-02 2026-04-16
CVE-2005-0856 CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnerability. [email protected] 7.5 0.49% 2005-05-02 2026-04-16
CVE-2005-0855 CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, (4) profile_notify.php, (5) profile_options.php, (6) profile_perso.php, (7) profile_pm.php, or (8) readannonce.php, which leaks the full pathname in a PHP error message. [email protected] 10.0 1.21% 2005-05-02 2026-04-16
CVE-2002-1515 Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter. [email protected] 5.0 1.39% 2003-04-02 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence