Freeguppy operates a narrowly focused content management or web platform product that attracts vulnerabilities concentrated in application-layer input handling and file-management mechanisms. The recurring signal centers on SQL injection and unrestricted file upload issues, which are characteristic weaknesses in web-facing systems that process untrusted user input and file submissions. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Freeguppy over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-31903CRITICAL GuppY CMS 6.00.10 is vulnerable to Unrestricted File Upload which allows remote attackers to execute arbitrary code by uploading a php file. | May 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2010-1740HIGH SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands via the lng parameter. | May 6, 2010 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Freeguppy.
Media articles that mention a CVE ID that affects a product developed by Freeguppy — matched by CVE ID, not by vendor name.