Aphpkb is a focused knowledge-base application whose vulnerability profile centers on input-handling flaws across its single product line. The recurring weakness classes—SQL injection, cross-site scripting, and code injection—reflect the application-layer risks inherent to a web-facing knowledge portal, and these flaws tend to acquire public exploit code. Defenders should prioritize this vendor's patches when the application is internet-reachable or processes untrusted content; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aphpkb over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1546HIGH Multiple SQL injection vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.3 allow remote attackers to execute arbitrary SQL commands via the s parameter to (1) a_view | Apr 4, 2011 | 7.5 | 36 | NO | YES |
CVE-2011-1556MEDIUM SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote attackers to execute arbitrary SQL commands via the pdfa para | Apr 4, 2011 | 6.8 | 29 | NO | YES |
CVE-2008-6513MEDIUM Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to execute arbitrary code by uploading a file with an executab | Mar 24, 2009 | 6.8 | 27 | NO | YES |
CVE-2011-1555MEDIUM SQL injection vulnerability in saa.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.3 and earlier allows remote attackers to execute arbitrary SQL commands via the aid parameter, a di | Apr 4, 2011 | 6.8 | 20 | NO | NO |
CVE-2013-7289MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in register.php in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML | Jan 10, 2014 | 4.3 | 17 | NO | NO |
CVE-2013-7277MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) HTT | Jan 8, 2014 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aphpkb.
Media articles that mention a CVE ID that affects a product developed by Aphpkb — matched by CVE ID, not by vendor name.