stphp CVE Vulnerabilities & CVE List (3)

Products (CPE): — CVEs: 3

stphp vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to stphp, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 13 of 3 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2007-3331 Cross-site request forgery (CSRF) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to change the admin password via (1) a certain HTML form that is posted automatically by JavaScript or (2) a news post. [email protected] 5.0 0.38% 2007-06-21 2026-04-23
CVE-2007-3330 Cross-site scripting (XSS) vulnerability in STphp EasyNews PRO 4.0 allows remote attackers to inject arbitrary web script or HTML via a news post, which is stored in news/ without sanitization. [email protected] 4.3 0.35% 2007-06-21 2026-04-23
CVE-2006-6866 STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames, email addresses, and password hashes via a direct request for data/users.txt. [email protected] 7.8 7.72% 2006-12-31 2026-04-23
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence