Coolforum maintains a focused forum software product with a modest presence in the vulnerability landscape, yet its disclosures carry an elevated tendency toward public exploit availability that warrants attention from operators running the software. The observed weaknesses cluster broadly around input handling and application logic, reflecting the attack surface typical of web-based community platforms. Operators should prioritize tracking and applying Coolforum updates; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Coolforum over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-2867HIGH SQL injection vulnerability in editpost.php in CoolForum 0.8.3 beta and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter. | Jun 6, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-0858HIGH Multiple SQL injection vulnerabilities in CoolForum 0.8 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to entete.php or (2) the l | May 2, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0855HIGH CoolForum 0.8.1 beta and earlier allows remote attackers to obtain sensitive path information via direct requests to (1) entete.php, (2) profile_accueil.php, (3) profile_mdp.php, ( | May 2, 2005 | 10.0 | 25 | NO | NO |
CVE-2005-0857MEDIUM Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter. | May 2, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-0856HIGH CoolForum 0.8.1 beta and earlier allows remote attackers to manipulate SQL commands via certain requests to (1) alert.php or (2) viewip.php, possibly due to a SQL injection vulnera | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2002-1515MEDIUM Directory traversal vulnerability in avatar.php in CoolForum 0.5 beta allows remote attackers to read arbitrary files via .. (dot dot) sequences in the img parameter. | Apr 2, 2003 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Coolforum.
Media articles that mention a CVE ID that affects a product developed by Coolforum — matched by CVE ID, not by vendor name.