Kwsphp is a niche web-application platform with a narrowly scoped product portfolio centered on the core Kwsphp system and its Galerie module, where the durable exposure signal reflects classic web-application input-handling deficiencies. Vulnerabilities affecting this vendor recur through SQL injection, path traversal, and cross-site scripting weaknesses that stem from insufficient input validation and output encoding in web contexts, and publicly available exploit code has frequently accompanied disclosures in this space. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kwsphp over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4956HIGH Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the pseudo parameter to login.php, (2) the id parameter to ind | Sep 18, 2007 | 7.5 | 32 | NO | YES |
CVE-2008-1758HIGH SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the C_ID parameter to index.php. | Apr 12, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-6197HIGH SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arbitrary SQL commands via the id_gal parameter in a gal action | Feb 20, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-1759HIGH SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the cat parameter to index.php, a different vector than | Apr 12, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-5485HIGH SQL injection vulnerability in index.php in the mg2 1.0 module for KwsPHP allows remote attackers to execute arbitrary SQL commands via the album parameter. | Oct 16, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-4979HIGH SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a results action, a | Sep 19, 2007 | 7.5 | 28 | NO | YES |
CVE-2008-6201MEDIUM Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allows remote attackers to execute arbitrary commands via the ac | Feb 20, 2009 | 6.8 | 27 | NO | YES |
CVE-2007-4922MEDIUM SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a play ac | Sep 17, 2007 | 6.5 | 27 | NO | YES |
CVE-2008-1757MEDIUM Cross-site scripting (XSS) vulnerability in index.php in the ConcoursPhoto module for KwsPHP 1.0 allows remote attackers to inject arbitrary web script or HTML via the VIEW paramet | Apr 12, 2008 | 4.3 | 23 | NO | YES |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kwsphp.
Media articles that mention a CVE ID that affects a product developed by Kwsphp — matched by CVE ID, not by vendor name.