phpnews CVE Vulnerabilities & CVE List (7)

Products (CPE): — CVEs: 7

phpnews vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to phpnews, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 17 of 7 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2006-7081 Multiple PHP remote file inclusion vulnerabilities in PhpNews 1.0 allow remote attackers to execute arbitrary PHP code via the Include parameter to (1) Include/lib.inc.php3 and (2) Include/variables.php3. [email protected] 7.5 8.51% 2007-03-02 2026-04-23
CVE-2006-6357 Cross-site scripting (XSS) vulnerability in templates/cat_temp.php in PHPNews 1.3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. [email protected] 6.8 0.87% 2006-12-07 2026-04-23
CVE-2006-6356 Multiple cross-site scripting (XSS) vulnerabilities in templates/link_temp.php in PHPNews 1.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) url, (2) id, (3) subject, (4) username, or (5) time parameter. [email protected] 6.8 0.80% 2006-12-07 2026-04-23
CVE-2005-2383 SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request. [email protected] 7.5 0.36% 2005-07-26 2026-04-16
CVE-2005-2156 SQL injection vulnerability in news.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the prevnext parameter. [email protected] 7.5 0.40% 2005-07-06 2026-04-16
CVE-2005-0632 PHP remote file inclusion vulnerability in auth.php in PHPNews 1.2.4 and possibly 1.2.3, allows remote attackers to execute arbitrary PHP code via the path parameter. [email protected] 5.0 4.24% 2005-03-01 2026-04-16
CVE-2004-2474 SQL injection vulnerability in PHPNews 1.2.3 allows remote attackers to execute arbitrary SQL commands via the mid parameter to sendtofriend.php. [email protected] 7.5 0.62% 2004-12-31 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence