Insanevisions develops a focused line of content management and community forum platforms, including OneCMS, AdaptCMS, BlogPHP, and AdaptBB, that serve small to mid-market web publishers and administrators. The vendor's vulnerability profile centers on input-handling weaknesses endemic to web applications—SQL injection, code injection, cross-site scripting, and path traversal—which recur across its product portfolio and reflect the parsing and output-encoding demands of user-facing web software. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Insanevisions over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1060MEDIUM Open redirect vulnerability in lib/Cake/Controller/Controller.php in AdaptCMS 3.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks vi | Jan 16, 2015 | 5.8 | 30 | NO | YES |
CVE-2010-2618MEDIUM PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code | Jul 2, 2010 | 6.8 | 30 | NO | YES |
CVE-2008-7209HIGH Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows remote attackers to execute arbitrary code by uploading a file | Sep 11, 2009 | 7.5 | 30 | NO | YES |
CVE-2008-2482HIGH Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the load | May 28, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-6652HIGH SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the sitename parameter. | Apr 7, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-5016HIGH SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands via the abc parameter. | Sep 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-0372HIGH Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username | Jan 22, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0318HIGH SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via | Jan 19, 2006 | 7.5 | 28 | NO | YES |
CVE-2015-1059MEDIUM Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension | Jan 16, 2015 | 6.5 | 27 | NO | YES |
CVE-2010-0952MEDIUM SQL injection vulnerability in index.php in OneCMS 2.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an el | Mar 10, 2010 | 6.8 | 26 | NO | YES |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Insanevisions.
Media articles that mention a CVE ID that affects a product developed by Insanevisions — matched by CVE ID, not by vendor name.