Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Flatnuke

First CVE: Jan 3, 2005Active for: 22 yearsTotal CVEs: 22
38.5
VTI Score
Medium

Flatnuke is a lightweight, self-hosted content management and website-building platform that has accumulated a durable vulnerability footprint across its single product line. The vulnerabilities affecting this vendor cluster around web-application and session-handling weaknesses—cross-site request forgery, forced-browsing issues, code injection, and improper input controls—that are characteristic of PHP-based CMS platforms and reflect common pitfalls in user-facing content management. Notably, this vendor's vulnerabilities frequently acquire public exploit code, a pattern consistent with the platform's open-source nature and the relative accessibility of CMS-targeted exploitation tooling. Defenders deploying or maintaining Flatnuke installations should prioritize patching these disclosures and restrict administrative access; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
7.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
5.4
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Flatnuke over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 3, 2005
21 years ago
Most Recent CVE
Sep 26, 2007
6,877 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-1894HIGH
Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which ca
Jun 9, 20057.529NOYES
CVE-2005-4448HIGH
FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to
Dec 21, 200510.027NONO
CVE-2005-2540MEDIUM
CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the
Aug 10, 20055.026NOYES
CVE-2005-4208MEDIUM
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.
Dec 13, 20055.025NOYES
CVE-2005-2813MEDIUM
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) character
Sep 7, 20055.025NOYES
CVE-2005-3307MEDIUM
Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operatio
Oct 26, 20055.023NOYES
CVE-2005-1893MEDIUM
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.
Jun 9, 20055.023NOYES
CVE-2006-3608MEDIUM
The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, w
Jul 18, 20064.622NOYES
CVE-2005-4449MEDIUM
verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into
Dec 21, 20054.022NOYES
CVE-2005-2814MEDIUM
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php.
Sep 7, 20054.321NOYES
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
82%
18%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown22 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown22 (100.0%)
User Interaction
None0 (0.0%)
Unknown22 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown22 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
11 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Flatnuke.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Flatnuke — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Flatnuke's Products

View all 1 CNAs →

Top CWEs