Guppy is a narrowly scoped content management system whose vulnerability profile concentrates in its core product and recurs across application-layer weaknesses including code injection, path traversal, and cross-site scripting that reflect typical input-handling and output-encoding risks in server-side web platforms. The vendor's disclosures have frequently acquired public exploit tooling, making timely patching and input sanitization controls material to deployments. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Guppy over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-0639HIGH Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject arbitrary PHP code into a .inc file in the data/ directory | Jan 31, 2007 | 7.5 | 31 | NO | YES |
CVE-2007-5845HIGH Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the id | Nov 6, 2007 | 7.5 | 29 | NO | YES |
CVE-2005-3926HIGH Direct static code injection vulnerability in error.php in GuppY 4.5.9 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via the | Nov 30, 2005 | 7.5 | 29 | NO | YES |
CVE-2005-3927MEDIUM Multiple directory traversal vulnerabilities in GuppY 4.5.9 and earlier allow remote attackers to read and include arbitrary files via (1) the meskin parameter to admin/editorTypet | Nov 30, 2005 | 6.4 | 29 | NO | YES |
CVE-2007-5844HIGH Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the selskin paramete | Nov 6, 2007 | 7.5 | 28 | NO | YES |
Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter. | Mar 14, 2006 | 2.6 | 19 | NO | YES |
CVE-2007-1451MEDIUM GuppY 4.0 allows remote attackers to delete arbitrary files via a direct request to install/install.php, then selecting "Installation propre" (cleanup.php) and then "Suppression de | Mar 14, 2007 | 6.4 | 18 | NO | NO |
CVE-2013-5983MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in GuppY before 4.6.28 allow remote attackers to inject arbitrary web script or HTML via the (1) "an" parameter to agenda.php or | Feb 6, 2014 | 4.3 | 14 | NO | NO |
CVE-2005-2853MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in GuppY 4.5.3a and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the pg parameter to printfaq.p | Sep 8, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Guppy.
Media articles that mention a CVE ID that affects a product developed by Guppy — matched by CVE ID, not by vendor name.