Campware.Org maintains Campsite, a web-based content management and publishing platform, with a vulnerability pattern centered on application-layer input handling and code generation. The recurring weakness classes—code injection, path traversal, cross-site scripting, and SQL injection—reflect the parser and database-interaction demands typical of web CMS products and indicate exposure to web-tier attack patterns. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Campware.Org over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-2183HIGH Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possibly execute arbitrary local files via a .. (dot dot) in the G | Jun 23, 2009 | 7.5 | 30 | NO | YES |
CVE-2006-5910HIGH Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot paramet | Nov 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-5911HIGH Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 2.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the g_documentRoot parameter | Nov 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2009-2182MEDIUM Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[g_campsiteDir] parameter to ( | Jun 23, 2009 | 6.8 | 26 | NO | YES |
CVE-2006-5912HIGH Unspecified vulnerability in Campware Campsite before 2.6.2 has unknown impact and attack vectors, related to a "Security fix for you-know-what," possibly related to encrypted pass | Nov 15, 2006 | 10.0 | 25 | NO | NO |
CVE-2010-1867HIGH SQL injection vulnerability in the ArticleAttachment::GetAttachmentsByArticleNumber method in javascript/tinymcs/plugins/campsiteattachment/attachments.php in Campsite 3.3.5 and ea | May 7, 2010 | 7.5 | 22 | NO | NO |
CVE-2009-2181MEDIUM Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attackers to inject arbitrary web script or HTML via the listbase | Jun 23, 2009 | 4.3 | 21 | NO | YES |
CVE-2005-4661MEDIUM The notifyendsubs cron job in Campsite before 2.3.3 sends an e-mail message containing a certain unencrypted MySQL password, which allows remote attackers to sniff the password. | Dec 31, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Campware.Org.
Media articles that mention a CVE ID that affects a product developed by Campware.Org — matched by CVE ID, not by vendor name.