Boka's vulnerability profile centers on its SiteEngine product, a web-based platform where the recurring weakness classes reflect common application-layer input-handling risks: SQL injection, improper input validation, and exposure of sensitive information. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Boka over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-7269MEDIUM Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in th | Dec 1, 2010 | 5.8 | 39 | NO | YES |
CVE-2010-4357HIGH SQL injection vulnerability in comments.php in SiteEngine 7.1 allows remote attackers to execute arbitrary SQL commands via the module parameter. | Dec 1, 2010 | 7.5 | 32 | NO | YES |
CVE-2008-7267HIGH SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 1, 2010 | 7.5 | 32 | NO | YES |
CVE-2008-7268MEDIUM The phpinfo function in SiteEngine 5.x allows remote attackers to obtain system information by setting the action parameter to php_info in misc.php. | Dec 1, 2010 | 5.0 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Boka.
Media articles that mention a CVE ID that affects a product developed by Boka — matched by CVE ID, not by vendor name.