Constructr is a narrowly scoped content management system vendor whose vulnerability exposure centers on its CMS product and reflects classic web-application input-handling weaknesses, specifically path traversal and SQL injection flaws. Current severity, exploitation activity, and detailed exposure counts are shown in the live panel alongside this summary.
The number and severity of CVEs published that impact products developed by Constructr over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5860MEDIUM Directory traversal vulnerability in backend/template.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote att | Jan 6, 2009 | 5.1 | 23 | NO | YES |
CVE-2008-5859MEDIUM SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute | Jan 6, 2009 | 5.1 | 22 | NO | YES |
Constructr CMS 3.02.5 and earlier stores passwords in cleartext in a MySQL database, which allows context-dependent attackers to obtain sensitive information by reading the hash co | Jan 5, 2009 | 2.6 | 18 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Constructr.
Media articles that mention a CVE ID that affects a product developed by Constructr — matched by CVE ID, not by vendor name.