Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Diangemilang

First CVE: May 24, 2006Active for: 20 yearsTotal CVEs: 6

Diangemilang maintains a narrowly scoped product portfolio centered on the DGNews application, a web-based news management system. The recurring vulnerability pattern reflects common application-layer weaknesses in SQL injection, typical of web-facing news and content-management platforms where database query construction from user input remains a structural risk. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
Bottom 1%
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 11% of tracked vendors
5.6
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Diangemilang over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 24, 2006
20 years ago
Most Recent CVE
May 21, 2009
6,277 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-1746HIGH
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.
May 21, 20097.529NOYES
CVE-2007-0693MEDIUM
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can
May 30, 20076.826NOYES
CVE-2007-0694MEDIUM
Cross-site scripting (XSS) vulnerability in footer.php in DGNews 2.1 allows remote attackers to inject arbitrary web script or HTML via the copyright parameter.
May 30, 20074.321NOYES
CVE-2007-2994HIGH
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the newsid parameter in a fullnews action, a different vector th
Jun 4, 20077.519NONO
CVE-2006-2573MEDIUM
SQL injection vulnerability in index.php in DGBook 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) h
May 24, 20065.115NONO
CVE-2006-2572LOW
Cross-site scripting (XSS) vulnerability in index.php in DGBook 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) homepage, (3) email, and (4
May 24, 20062.612NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
17%
50%
33%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown6 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown6 (100.0%)
User Interaction
None0 (0.0%)
Unknown6 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown6 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
50.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Diangemilang.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Diangemilang — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Diangemilang's Products

View all 1 CNAs →

Top CWEs