Cpaint is a narrowly scoped graphics and painting application with a modest recorded vulnerability footprint. The observed weakness classes are categorized under general or placeholder classifications, limiting the structural clarity for defenders tracking this vendor; live severity, exploitation, and exposure details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cpaint over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0650MEDIUM Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script | Feb 13, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-2625HIGH Incomplete blacklist vulnerability in the checkBlacklist function in CPAINT allows remote attackers to execute arbitrary commands via the (1) ExecuteGlobal function or (2) GetRef s | Aug 19, 2005 | 7.5 | 20 | NO | NO |
CVE-2005-2613MEDIUM Unknown vulnerability in CPAINT Ajax Toolkit before 1.3-SP allows attackers to execute arbitrary PHP or ASP code or read files via unknown vectors. | Aug 17, 2005 | 6.4 | 17 | NO | NO |
CVE-2005-2624MEDIUM Eval injection vulnerability in CPAINT 1.3-SP allows remote attackers to execute arbitrary ASP code via the cpaint_argument[] parameter to (1) calculator.asp or (2) cpaintfile.asp, | Aug 19, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cpaint.
Media articles that mention a CVE ID that affects a product developed by Cpaint — matched by CVE ID, not by vendor name.