Phpkb
Vendor:
First CVE: Mar 12, 2020 · Active for 6 years
119
Total CVEs
More Total CVEs than 99% of tracked products
119.0
Avg CVEs / Year
Higher CVE frequency than 100% of tracked products
4.9
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Phpkb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 12, 2020
6 years ago
Most Recent CVE
Sep 3, 2020
2,152 days ago
CVE Severity & Scoring
Phpkb119 CVEs
94%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network119 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low119 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None9 (7.6%)
Unknown0 (0.0%)
Required110 (92.4%)
Privileges Required
Low1 (0.8%)
High89 (74.8%)
None29 (24.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (119 CVEs).
119 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-10386HIGH admin/imagepaster/image-upload.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by uploading a .php file in the admin/js/ directory. | Mar 12, 2020 | 7.2 | 33 | NO | YES |
CVE-2020-11579HIGH An issue was discovered in Chadha PHPKB 9.0 Enterprise Edition. installer/test-connection.php (part of the installation process) allows a remote unauthenticated attacker to disclos | Sep 3, 2020 | 7.5 | 32 | NO | NO |
CVE-2020-10387MEDIUM Path Traversal in admin/download.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to download files from the server using a dot-dot-slash sequence (../) via th | Mar 12, 2020 | 4.9 | 30 | NO | YES |
CVE-2020-10390HIGH OS Command Injection in export.php (vulnerable function called from include/functions-article.php) in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code | Mar 12, 2020 | 7.2 | 24 | NO | NO |
CVE-2020-10478HIGH CSRF in admin/manage-settings.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to change the global settings, potentially gaining code execution or causing a denial o | Mar 12, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-10501MEDIUM CSRF in admin/manage-departments.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to edit a department, given the id, via a crafted request. | Mar 12, 2020 | 6.5 | 21 | NO | NO |
CVE-2020-10458MEDIUM Path Traversal in admin/imagepaster/operations.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete any folder on the webserver using a dot-dot-slash sequence ( | Mar 12, 2020 | 6.5 | 20 | NO | NO |
CVE-2020-10389HIGH admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global | Mar 12, 2020 | 7.2 | 20 | NO | NO |
CVE-2020-10487MEDIUM CSRF in admin/manage-glossary.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to delete a glossary term via a crafted request. | Mar 12, 2020 | 4.3 | 18 | NO | NO |
CVE-2020-10483MEDIUM CSRF in admin/ajax-hub.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to post a comment on any article via a crafted request. | Mar 12, 2020 | 4.3 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (119 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
1.7% of CVEs· 87th percentile
Social Chatter
Signals from CVEs in this product scope (119 CVEs).
Media Mentions
Signals from CVEs in this product scope (119 CVEs).
Top CNAs Publishing CVEs For Phpkb
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.0 | 119 | 4.9 | 1.1% | 0 | 2 |