Dmsguestbook Project maintains a niche guestbook application that exhibits vulnerabilities concentrated in web application input handling and data access layers. The recurring weakness classes center on cross-site scripting, path traversal, and SQL injection, which are characteristic of application-tier flaws in user-facing web components. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dmsguestbook Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0616MEDIUM SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote authenticated administrators to execute arbitrary SQL commands | Feb 6, 2008 | 6.5 | 29 | NO | YES |
CVE-2008-0617MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) file pa | Feb 6, 2008 | 4.3 | 17 | NO | NO |
CVE-2008-0618MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the ( | Feb 6, 2008 | 4.3 | 17 | NO | NO |
CVE-2008-0615MEDIUM Directory traversal vulnerability in wp-admin/admin.php in the DMSGuestbook 1.8.0 and 1.7.0 plugin for WordPress allows remote authenticated users to read arbitrary files via a .. | Feb 6, 2008 | 4.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dmsguestbook Project.
Media articles that mention a CVE ID that affects a product developed by Dmsguestbook Project — matched by CVE ID, not by vendor name.