Keir Davis maintains the X-Forum application, which presents a focused web application footprint centered on dynamic content and database interaction. The vendor's observed vulnerability signal reflects application-layer input-handling weaknesses, specifically code injection and SQL injection, which are characteristic of server-side scripting frameworks. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keir Davis over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1508HIGH SQL injection vulnerability in the xforum_validateUser function in Common.php in X-Forum 0.6.2 allows remote attackers to execute arbitrary SQL commands, as demonstrated via the co | May 1, 2009 | 7.5 | 30 | NO | YES |
CVE-2009-1512MEDIUM Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP code into Config.php via the adminEMail parameter to SaveCon | May 1, 2009 | 6.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keir Davis.
Media articles that mention a CVE ID that affects a product developed by Keir Davis — matched by CVE ID, not by vendor name.