Mkportal is a web portal platform with a narrow product footprint that recurs in a prominent position within the vulnerability landscape, spanning the core portal application and its NoBoard module extension. The vendor's disclosures cluster around application-layer input-handling and state-management weaknesses—SQL injection, cross-site scripting, and cross-site request forgery—that are characteristic of web-facing PHP and script-based portal software, and the exposure frequently acquires public exploit code. Defenders deploying this portal should prioritize input validation hardening and cross-origin request controls; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mkportal over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3813MEDIUM PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH p | Jul 17, 2007 | 4.3 | 52 | NO | YES |
CVE-2007-6467HIGH SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action. | Dec 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3814HIGH Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index. | Jul 17, 2007 | 7.5 | 28 | NO | YES |
CVE-2006-2067HIGH SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the u | Apr 27, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-6741MEDIUM Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBc | Dec 26, 2006 | 5.8 | 24 | NO | YES |
CVE-2007-0194HIGH admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error messa | Jan 12, 2007 | 7.8 | 23 | NO | NO |
CVE-2007-3637HIGH SQL injection vulnerability in MKPortal 1.1.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZD-00000008. this information is based upon a | Jul 10, 2007 | 7.5 | 21 | NO | NO |
CVE-2006-2066MEDIUM Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitra | Apr 27, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-3554HIGH Directory traversal vulnerability in index.php in MKPortal 1.0.1 Final allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the | Jul 13, 2006 | 7.5 | 20 | NO | NO |
CVE-2007-0192HIGH Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as | Jan 12, 2007 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mkportal.
Media articles that mention a CVE ID that affects a product developed by Mkportal — matched by CVE ID, not by vendor name.