In Portal is a niche portal and collaboration platform with a narrowly scoped vulnerability footprint concentrated in its single product line. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by In Portal over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-4986MEDIUM Directory traversal vulnerability in index.php in In-Portal 4.3.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the env | Aug 25, 2010 | 6.8 | 29 | NO | YES |
CVE-2014-8304MEDIUM Cross-site scripting (XSS) vulnerability in In-Portal CMS 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the next_template parameter to admin/ | Oct 16, 2014 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by In Portal.
Media articles that mention a CVE ID that affects a product developed by In Portal — matched by CVE ID, not by vendor name.