Flatnuke is a lightweight, self-hosted content management and website-building platform that has accumulated a durable vulnerability footprint across its single product line. The vulnerabilities affecting this vendor cluster around web-application and session-handling weaknesses—cross-site request forgery, forced-browsing issues, code injection, and improper input controls—that are characteristic of PHP-based CMS platforms and reflect common pitfalls in user-facing content management. Notably, this vendor's vulnerabilities frequently acquire public exploit code, a pattern consistent with the platform's open-source nature and the relative accessibility of CMS-targeted exploitation tooling. Defenders deploying or maintaining Flatnuke installations should prioritize patching these disclosures and restrict administrative access; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flatnuke over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-1894HIGH Direct code injection vulnerability in FlatNuke 2.5.3 allows remote attackers to execute arbitrary PHP code by placing the code into the Referer header of an HTTP request, which ca | Jun 9, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-4448HIGH FlatNuke 2.5.6 verifies authentication credentials based on an MD5 checksum of the admin name and the hashed password rather than the plaintext password, which allows attackers to | Dec 21, 2005 | 10.0 | 27 | NO | NO |
CVE-2005-2540MEDIUM CRLF injection vulnerability in FlatNuke 2.5.5 and possibly earlier versions allows remote attackers to execute arbitrary PHP commands via an ASCII char 13 (carriage return) in the | Aug 10, 2005 | 5.0 | 26 | NO | YES |
CVE-2005-4208MEDIUM Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module. | Dec 13, 2005 | 5.0 | 25 | NO | YES |
CVE-2005-2813MEDIUM Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files via ".." sequences and "%00" (trailing null byte) character | Sep 7, 2005 | 5.0 | 25 | NO | YES |
CVE-2005-3307MEDIUM Directory traversal vulnerability in index.php for FlatNuke 2.5.6 allows remote attackers to read arbitrary files via ".." sequences in the (1) user parameter in a profile operatio | Oct 26, 2005 | 5.0 | 23 | NO | YES |
CVE-2005-1893MEDIUM FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message. | Jun 9, 2005 | 5.0 | 23 | NO | YES |
CVE-2006-3608MEDIUM The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, w | Jul 18, 2006 | 4.6 | 22 | NO | YES |
CVE-2005-4449MEDIUM verify.php in FlatNuke 2.5.6 allows remote authenticated administrators to modify arbitrary PHP files by setting the file parameter to an arbitrary file and injecting the code into | Dec 21, 2005 | 4.0 | 22 | NO | YES |
CVE-2005-2814MEDIUM Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTML via the usr parameter in a vis_reg operation to index.php. | Sep 7, 2005 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flatnuke.
Media articles that mention a CVE ID that affects a product developed by Flatnuke — matched by CVE ID, not by vendor name.