DolphinPHP is a modestly represented PHP framework with a narrow vulnerability footprint centered on its core product and a durable signal around unrestricted file-upload handling. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dolphinphp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0935CRITICAL A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file common.php of the comp | Feb 21, 2023 | 9.8 | 32 | NO | NO |
CVE-2021-46097HIGH Dolphinphp v1.5.0 contains a remote code execution vulnerability in /application/common.php#action_log | Jan 27, 2022 | 8.8 | 27 | NO | NO |
CVE-2022-37254MEDIUM DolphinPHP 1.5.1 is vulnerable to Cross Site Scripting (XSS) via Background - > System - > system function - > configuration management. | Aug 19, 2022 | 5.4 | 20 | NO | NO |
CVE-2022-1086MEDIUM A vulnerability was found in DolphinPHP up to 1.5.0 and classified as problematic. Affected by this issue is the User Management Page. The manipulation leads to cross site scriptin | Mar 29, 2022 | 5.4 | 18 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dolphinphp.
Media articles that mention a CVE ID that affects a product developed by Dolphinphp — matched by CVE ID, not by vendor name.