Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Geeklog

First CVE: Mar 25, 2002Active for: 24 yearsTotal CVEs: 33
46.6
VTI Score
High

Geeklog is a PHP-based content management system and blogging platform with modest but durable deployment, particularly for niche and community-focused websites; its vulnerability footprint concentrates in the core Geeklog product and associated Media Gallery extension. The recurring exposure centers on application-layer input-handling weaknesses—notably cross-site scripting and SQL injection—alongside a broader category of web-generation flaws, consistent with the server-side rendering and database-interaction patterns common to PHP applications of its era. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting both the accessibility of PHP source code and the appeal of compromising small-to-medium-sized web properties. Defenders operating Geeklog installations should prioritize input-sanitization and parameterized-query mitigations and maintain close monitoring of plugin and extension dependencies; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 97% of tracked vendors
1.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 30% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Geeklog over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2002
24 years ago
Most Recent CVE
Oct 24, 2023
1,005 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-2793HIGH
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter.
May 22, 20077.564NOYES
CVE-2002-0962HIGH
Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event,
Oct 4, 20027.532NOYES
CVE-2010-4933HIGH
SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL commands via the lid parameter.
Oct 9, 20117.530NOYES
CVE-2007-0810HIGH
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_librarie
Feb 7, 20077.530NOYES
CVE-2007-2706HIGH
PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the
May 16, 20077.529NOYES
CVE-2006-0823HIGH
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid varia
Feb 21, 20067.528NOYES
CVE-2006-2699MEDIUM
Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a
May 31, 20066.827NOYES
CVE-2006-1069HIGH
Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers
Mar 7, 200610.025NONO
CVE-2006-6225MEDIUM
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc
Dec 2, 20065.124NOYES
CVE-2006-3362MEDIUM
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka
Jul 6, 20065.124NOYES
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
58%
42%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network5 (15.2%)
Unknown28 (84.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (15.2%)
High0 (0.0%)
Unknown28 (84.8%)
User Interaction
None0 (0.0%)
Unknown28 (84.8%)
Required5 (15.2%)
Privileges Required
Low0 (0.0%)
High4 (12.1%)
None1 (3.0%)
Unknown28 (84.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
10 CVEs
30.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Geeklog.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Geeklog — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Geeklog's Products

View all 3 CNAs →

Top CWEs