Envolution offers a narrowly focused product line centered on its core platform, which has been associated with application-layer input-handling vulnerabilities, particularly SQL injection. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Envolution over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6445HIGH Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVla | Dec 10, 2006 | 7.5 | 31 | NO | YES |
CVE-2007-4253HIGH SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter, a d | Aug 8, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-4263HIGH SQL injection vulnerability in the News module in Envolution allows remote attackers to execute arbitrary SQL commands via the (1) startrow and (2) catid parameter. | Dec 15, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-4262MEDIUM Cross-site scripting (XSS) vulnerability in the News module in Envolution allows remote attackers to inject arbitrary web script or HTML via the (1) startrow and (2) catid paramete | Dec 15, 2005 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Envolution.
Media articles that mention a CVE ID that affects a product developed by Envolution — matched by CVE ID, not by vendor name.