Clansphere is a niche community and clan-management platform whose vulnerability profile centers on a single application product with a durable signal rooted in web-application input-handling flaws. The recurring weakness classes—cross-site scripting, SQL injection, and path traversal—reflect the parsing and validation demands of a web application that processes user-supplied content, and this class of flaw has frequently acquired public exploit tooling and proof-of-concept code. Defenders deploying this platform should prioritize input validation hardening and treat publicly disclosed vulnerabilities in this category as actively exploitable; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Clansphere over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5061HIGH SQL injection vulnerability in mods/banners/navlist.php in Clansphere 2007.4 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter to index.php in a ba | Sep 24, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-0489MEDIUM Directory traversal vulnerability in install.php in Clansphere 2007.4.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang paramete | Jan 30, 2008 | 5.0 | 23 | NO | YES |
CVE-2009-2438MEDIUM Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the | Jul 13, 2009 | 4.3 | 21 | NO | YES |
CVE-2009-2345HIGH Multiple SQL injection vulnerabilities in ClanSphere before 2009.0.1 allow remote attackers to execute arbitrary SQL commands via unknown parameters to the gbook module and unspeci | Jul 7, 2009 | 7.5 | 19 | NO | NO |
CVE-2008-1399MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in Clansphere 2008 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: th | Mar 20, 2008 | 4.3 | 16 | NO | NO |
CVE-2008-6470MEDIUM Multiple unspecified vulnerabilities in ClanSphere before 2008.2.1 allow remote attackers to obtain sensitive information, and possibly have unknown other impact, via vectors relat | Mar 13, 2009 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Clansphere.
Media articles that mention a CVE ID that affects a product developed by Clansphere — matched by CVE ID, not by vendor name.