myphpnuke CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

myphpnuke vulnerability overview

Aggregates CVE and security vulnerability intelligence across all myphpnuke-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Common weakness patterns include vendor risk sql injection and vendor risk cross-site scripting, with potential vendor impact session compromise and vendor impact data exposure across vendor surface software deployment use cases.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2008-4092 SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter. [email protected] 7.5 0.80% 2008-09-15 2026-04-23
CVE-2008-4089 Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. [email protected] 4.3 3.13% 2008-09-15 2026-04-23
CVE-2008-4088 SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter. [email protected] 7.5 0.80% 2008-09-15 2026-04-23
CVE-2006-6795 PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter. [email protected] 7.5 3.72% 2006-12-28 2026-04-23
CVE-2006-0923 Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php. [email protected] 4.3 11.15% 2006-02-28 2026-04-16
CVE-2003-1372 Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via the (1) ratenum or (2) query parameters. [email protected] 4.3 0.59% 2003-12-31 2026-04-16
CVE-2002-1913 phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable. [email protected] 5.0 0.46% 2002-12-31 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence