Cnstats is a narrowly scoped vendor with a focused product line centered on the cnstats application, representing a niche presence in the vulnerability landscape. The observed weakness characterization remains broad, and current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cnstats over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2086MEDIUM Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code via a URL in the bj parameter to (1) who_r.php or (2) who_s.p | Apr 18, 2007 | 6.8 | 28 | NO | YES |
CVE-2007-2087MEDIUM Multiple PHP remote file inclusion vulnerabilities in CNStats 2.12, when register_globals is enabled and .htaccess is not recognized, allow remote attackers to execute arbitrary PH | Apr 18, 2007 | 6.8 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cnstats.
Media articles that mention a CVE ID that affects a product developed by Cnstats — matched by CVE ID, not by vendor name.