Kubix is a focused vendor with a narrow product portfolio centered on a single product, and its disclosed vulnerabilities cluster around input-handling and access-control weaknesses such as path traversal and SQL injection. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kubix over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7116HIGH SQL injection vulnerability in includes/functions.php in Kubix 0.7 and earlier allows remote attackers to execute arbitrary SQL commands and bypass authentication via the member_id | Mar 6, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-7117MEDIUM Multiple directory traversal vulnerabilities in Kubix 0.7 and earlier allow remote attackers to (1) include and execute arbitrary local files via ".." sequences in the theme cookie | Mar 6, 2007 | 6.8 | 27 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kubix.
Media articles that mention a CVE ID that affects a product developed by Kubix — matched by CVE ID, not by vendor name.