Cutephp maintains a narrowly scoped portfolio centered around the CuteNews content-management system, a platform with notable prominence in web-hosting and small-business deployments despite limited active development. The vendor's vulnerability profile concentrates in web-application attack surface, with recurring weakness classes including code injection, cross-site scripting, path traversal, and cross-site request forgery—patterns typical of legacy PHP applications lacking input-validation and output-encoding rigor. Public exploit code has frequently emerged for vulnerabilities in this product line, reflecting both the accessibility of the codebase and the appeal of these classes to automated attack tools. Defenders should assume that CuteNews instances in production are likely to be exposed to public tooling and should prioritize inventory and isolation of affected systems, particularly in hosting and shared-infrastructure contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cutephp over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-11447HIGH An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.ph | Apr 22, 2019 | 8.8 | 67 | NO | YES |
CVE-2008-4557HIGH plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted | Oct 14, 2008 | 10.0 | 60 | NO | YES |
CVE-2003-1240HIGH PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.p | Dec 31, 2003 | 7.5 | 32 | NO | YES |
CVE-2005-3010HIGH Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code | Sep 21, 2005 | 7.5 | 30 | NO | YES |
CVE-2004-0660MEDIUM Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary scr | Aug 6, 2004 | 6.8 | 28 | NO | YES |
CVE-2006-1121MEDIUM Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php. | Mar 9, 2006 | 6.8 | 27 | NO | YES |
CVE-2005-3507MEDIUM Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parame | Nov 6, 2005 | 5.0 | 27 | NO | YES |
CVE-2009-4173MEDIUM Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for re | Dec 2, 2009 | 6.8 | 26 | NO | YES |
CVE-2009-4115MEDIUM Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inj | Nov 30, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-4174MEDIUM The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to | Dec 2, 2009 | 6.0 | 25 | NO | YES |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cutephp.
Media articles that mention a CVE ID that affects a product developed by Cutephp — matched by CVE ID, not by vendor name.