memht CVE Vulnerabilities & CVE List (5)

Products (CPE): — CVEs: 5

memht vulnerability overview

Aggregates CVE and security vulnerability intelligence across all memht-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection and vendor risk csrf and related problems; some flaws may lead to vendor impact data exposure, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 15 of 5 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2010-5320 Multiple cross-site request forgery (CSRF) vulnerabilities in MemHT Portal 4.0.1 allow remote attackers to hijack the authentication of administrators for requests that (1) modify settings via a configuration action to admin.php, (2) modify articles via an articles action to admin.php, or (3) modify credentials via a users action to admin.php. [email protected] 6.8 0.12% 2015-01-03 2026-05-06
CVE-2009-0372 Unrestricted file upload vulnerability in index.php in Miltenovik Manojlo MemHT Portal 4.0.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and an image content type via a users editProfile action, then accessing this file via a direct request to the file in images/avatar/uploaded/. [email protected] 6.5 3.50% 2009-01-30 2026-04-23
CVE-2008-5132 SQL injection vulnerability in inc/ajax/ajax_rating.php in MemHT Portal 4.0.1 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header. [email protected] 7.5 0.91% 2008-11-18 2026-04-23
CVE-2008-4457 SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via a stats_res cookie to index.php. [email protected] 6.8 1.38% 2008-10-07 2026-04-23
CVE-2008-4164 cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message. [email protected] 2.6 5.09% 2008-09-22 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence