Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cutephp

First CVE: Dec 31, 2003Active for: 23 yearsTotal CVEs: 39
44.3
VTI Score
High

Cutephp maintains a narrowly scoped portfolio centered around the CuteNews content-management system, a platform with notable prominence in web-hosting and small-business deployments despite limited active development. The vendor's vulnerability profile concentrates in web-application attack surface, with recurring weakness classes including code injection, cross-site scripting, path traversal, and cross-site request forgery—patterns typical of legacy PHP applications lacking input-validation and output-encoding rigor. Public exploit code has frequently emerged for vulnerabilities in this product line, reflecting both the accessibility of the codebase and the appeal of these classes to automated attack tools. Defenders should assume that CuteNews instances in production are likely to be exposed to public tooling and should prioritize inventory and isolation of affected systems, particularly in hosting and shared-infrastructure contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
39
Total CVEs
More Total CVEs than 98% of tracked vendors
4.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 24% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cutephp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2003
22 years ago
Most Recent CVE
Mar 25, 2020
2,312 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (39 CVEs).

39 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11447HIGH
An issue was discovered in CutePHP CuteNews 2.1.2. An attacker can infiltrate the server through the avatar upload process in the profile area via the avatar_file field to index.ph
Apr 22, 20198.867NOYES
CVE-2008-4557HIGH
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute arbitrary PHP code via the text parameter, which is inserted
Oct 14, 200810.060NOYES
CVE-2003-1240HIGH
PHP remote file inclusion vulnerability in CuteNews 0.88 allows remote attackers to execute arbitrary PHP code via a URL in the cutepath parameter in (1) shownews.php, (2) search.p
Dec 31, 20037.532NOYES
CVE-2005-3010HIGH
Direct static code injection vulnerability in the flood protection feature in inc/shows.inc.php in CuteNews 1.4.0 and earlier allows remote attackers to execute arbitrary PHP code
Sep 21, 20057.530NOYES
CVE-2004-0660MEDIUM
Cross-site scripting (XSS) vulnerability in (1) show_archives.php, (2) show_news.php, and possibly other php files in CuteNews 1.3.1 allows remote attackers to inject arbitrary scr
Aug 6, 20046.828NOYES
CVE-2006-1121MEDIUM
Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.
Mar 9, 20066.827NOYES
CVE-2005-3507MEDIUM
Directory traversal vulnerability in CuteNews 1.4.1 allows remote attackers to include arbitrary files, execute code, and gain privileges via "../" sequences in the template parame
Nov 6, 20055.027NOYES
CVE-2009-4173MEDIUM
Cross-site request forgery (CSRF) vulnerability in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b allows remote attackers to hijack the authentication of administrators for re
Dec 2, 20096.826NOYES
CVE-2009-4115MEDIUM
Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authenticated users with application administrative privileges to inj
Nov 30, 20096.526NOYES
CVE-2009-4174MEDIUM
The editnews module in CutePHP CuteNews 1.4.6 and UTF-8 CuteNews before 8b, when magic_quotes_gpc is disabled, allows remote authenticated users with Journalist or Editor access to
Dec 2, 20096.025NOYES
View all 39 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products39 CVEs
10%
67%
23%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local1 (2.6%)
Network3 (7.7%)
Unknown35 (89.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (7.7%)
High1 (2.6%)
Unknown35 (89.7%)
User Interaction
None2 (5.1%)
Unknown35 (89.7%)
Required2 (5.1%)
Privileges Required
Low2 (5.1%)
High0 (0.0%)
None2 (5.1%)
Unknown35 (89.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (39 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
19 CVEs
48.7% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cutephp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cutephp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cutephp's Products

View all 2 CNAs →

Top CWEs