Minerva is a narrowly focused vendor with a single product bearing that name, presenting a compact vulnerability surface relative to the broader landscape. The observed disclosures cluster around classification as other or unspecified weakness categories, limiting clear structural patterns; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minerva over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3028HIGH PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL | Jun 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-1555HIGH SQL injection vulnerability in forum.php in the Minerva mod 2.0.21 build 238a and earlier for phpBB allows remote attackers to execute arbitrary SQL commands via the c parameter. | Mar 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-5077MEDIUM PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code v | Sep 29, 2006 | 5.1 | 23 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minerva.
Media articles that mention a CVE ID that affects a product developed by Minerva — matched by CVE ID, not by vendor name.