Fkrauthan's vulnerability footprint centers on web-based content management and PDF generation tools, including Phoenix View CMS and WordPress plugins, presenting a modest attack surface oriented toward web applications. The observed weakness classes—cross-site scripting, path traversal, and SQL injection—reflect the input-handling and file-access demands of web-facing publishing platforms; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fkrauthan over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-2535HIGH Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbitrary SQL commands via the del parameter to (1) gbuch.admin. | Jun 3, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-2534HIGH Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote attackers to include and execute arbitrary local files via a .. | Jun 3, 2008 | 7.5 | 28 | NO | YES |
CVE-2025-60040MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf wp-mpdf allows Stored XSS.This issue affects wp-mpdf: from n | Sep 26, 2025 | 6.5 | 22 | NO | NO |
CVE-2008-2533MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ltarget par | Jun 3, 2008 | 4.3 | 21 | NO | YES |
CVE-2024-27962MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Florian 'fkrauthan' Krauthan allows Reflected XSS.This issue affects wp-mpdf: | Mar 21, 2024 | 6.1 | 19 | NO | NO |
CVE-2021-4416MEDIUM The wp-mpdf plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.5.1. This is due to missing or incorrect nonce validation on the mp | Jul 12, 2023 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fkrauthan.
Media articles that mention a CVE ID that affects a product developed by Fkrauthan — matched by CVE ID, not by vendor name.