Flatnuke3 is a niche content-management or website-building platform with a focused product footprint, and its disclosed vulnerabilities center on application-layer weaknesses including cross-site request forgery, sensitive-information exposure, and code-injection flaws. These are characteristic of systems that parse user input and manage session state across web interfaces; treat this as a compact vendor profile where live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flatnuke3 over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-5771HIGH Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie. | Nov 1, 2007 | 7.5 | 30 | NO | YES |
CVE-2007-5772MEDIUM Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrators to inject arbitrary PHP code into a description.it.php fi | Nov 1, 2007 | 6.0 | 26 | NO | YES |
CVE-2007-5774MEDIUM index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invalid argumentname parameter in a disc op action, which reveals | Nov 1, 2007 | 5.0 | 23 | NO | YES |
CVE-2007-5773MEDIUM Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote attackers to perform certain actions as administrators via reque | Nov 1, 2007 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flatnuke3.
Media articles that mention a CVE ID that affects a product developed by Flatnuke3 — matched by CVE ID, not by vendor name.