Geeklog is a PHP-based content management system and blogging platform with modest but durable deployment, particularly for niche and community-focused websites; its vulnerability footprint concentrates in the core Geeklog product and associated Media Gallery extension. The recurring exposure centers on application-layer input-handling weaknesses—notably cross-site scripting and SQL injection—alongside a broader category of web-generation flaws, consistent with the server-side rendering and database-interaction patterns common to PHP applications of its era. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting both the accessibility of PHP source code and the appeal of compromising small-to-medium-sized web properties. Defenders operating Geeklog installations should prioritize input-sanitization and parameterized-query mitigations and maintain close monitoring of plugin and extension dependencies; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Geeklog over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2793HIGH PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_system] parameter. | May 22, 2007 | 7.5 | 64 | NO | YES |
CVE-2002-0962HIGH Cross-site scripting vulnerabilities in GeekLog 1.3.5 and earlier allow remote attackers to execute arbitrary script via (1) the url variable in the Link field of a calendar event, | Oct 4, 2002 | 7.5 | 32 | NO | YES |
CVE-2010-4933HIGH SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL commands via the lid parameter. | Oct 9, 2011 | 7.5 | 30 | NO | YES |
CVE-2007-0810HIGH PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the glConf[path_librarie | Feb 7, 2007 | 7.5 | 30 | NO | YES |
CVE-2007-2706HIGH PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows remote attackers to execute arbitrary PHP code via a URL in the | May 16, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-0823HIGH Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attackers to inject arbitrary SQL commands via the (1) userid varia | Feb 21, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-2699MEDIUM Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a | May 31, 2006 | 6.8 | 27 | NO | YES |
CVE-2006-1069HIGH Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 before 1.3.9sr5, and possibly earlier versions allows attackers | Mar 7, 2006 | 10.0 | 25 | NO | NO |
CVE-2006-6225MEDIUM Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a URL in the _CONF[path] parameter to (1) links/functions.inc | Dec 2, 2006 | 5.1 | 24 | NO | YES |
CVE-2006-3362MEDIUM Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) Geeklog 1.4.0 through 1.4.0sr3, (2) toendaCMS 1.0.0 Shizouka | Jul 6, 2006 | 5.1 | 24 | NO | YES |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Geeklog.
Media articles that mention a CVE ID that affects a product developed by Geeklog — matched by CVE ID, not by vendor name.