Exv2 maintains a small portfolio of web-based content management and gallery products that operate as widely accessible internet-facing applications, concentrating vulnerability exposure in systems that handle user input and file management. The vendor's disclosures skew toward serious outcomes and frequently acquire public exploit code, while the recurring weakness classes—SQL injection, improper authentication, path traversal, and dynamic code resource management—reflect the input-validation and access-control demands characteristic of web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exv2 over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7079CRITICAL Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and earlier allows remote attackers to overwrite arbitrary program variables and conduct directory traversal | Mar 2, 2007 | 9.8 | 47 | NO | YES |
CVE-2008-1407MEDIUM SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the roomid parameter. | Mar 20, 2008 | 6.8 | 30 | NO | YES |
CVE-2008-1406MEDIUM SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the lid parameter in an ImprAnn | Mar 20, 2008 | 6.8 | 28 | NO | YES |
CVE-2008-1349HIGH SQL injection vulnerability in viewcat.php in the bamaGalerie (Bama Galerie) 3.03 and 3.041 module for eXV2 2.0.6 allows remote attackers to execute arbitrary SQL commands via the | Mar 17, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-1966CRITICAL Session fixation vulnerability in eXV2 CMS 2.0.4.3 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID cookie. | Apr 11, 2007 | 9.1 | 28 | NO | NO |
CVE-2006-5030HIGH SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter. | Sep 27, 2006 | 7.5 | 28 | NO | YES |
CVE-2008-1404MEDIUM SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attackers to execute arbitrary SQL commands via the kid parameter. | Mar 20, 2008 | 6.8 | 26 | NO | YES |
CVE-2006-7080MEDIUM Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to delete arbitrary files via ".." sequences in the old_avatar pa | Mar 2, 2007 | 4.3 | 22 | NO | YES |
CVE-2010-4155MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in eXV2 CMS 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) rssfeedURL parameter to manual/cafers | Nov 3, 2010 | 4.3 | 17 | NO | NO |
CVE-2007-4365MEDIUM Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a set_lang cookie to an unspecified compon | Aug 15, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exv2.
Media articles that mention a CVE ID that affects a product developed by Exv2 — matched by CVE ID, not by vendor name.