Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mkportal

First CVE: Apr 27, 2006Active for: 20 yearsTotal CVEs: 13
49.9
VTI Score
TOP TARGET

Mkportal is a web portal platform with a narrow product footprint that recurs in a prominent position within the vulnerability landscape, spanning the core portal application and its NoBoard module extension. The vendor's disclosures cluster around application-layer input-handling and state-management weaknesses—SQL injection, cross-site scripting, and cross-site request forgery—that are characteristic of web-facing PHP and script-based portal software, and the exposure frequently acquires public exploit code. Defenders deploying this portal should prioritize input validation hardening and cross-origin request controls; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
3.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mkportal over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 27, 2006
20 years ago
Most Recent CVE
Dec 20, 2007
6,791 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-3813MEDIUM
PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attackers to execute arbitrary PHP code via a URL in the MK_PATH p
Jul 17, 20074.352NOYES
CVE-2007-6467HIGH
SQL injection vulnerability in index.php in MKPortal 1.1 RC1 allows remote attackers to execute arbitrary SQL commands via the ida parameter in a gallery foto_show action.
Dec 20, 20077.528NOYES
CVE-2007-3814HIGH
Multiple SQL injection vulnerabilities in MKPortal 1.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the idurlo field in the delete_urlo function in (a) index.
Jul 17, 20077.528NOYES
CVE-2006-2067HIGH
SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the u
Apr 27, 20067.528NOYES
CVE-2006-6741MEDIUM
Cross-site request forgery (CSRF) vulnerability in urlobox in MKPortal allows remote attackers to delete arbitrary messages as an administrator via a delete operation in an img BBc
Dec 26, 20065.824NOYES
CVE-2007-0194HIGH
admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error messa
Jan 12, 20077.823NONO
CVE-2007-3637HIGH
SQL injection vulnerability in MKPortal 1.1.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZD-00000008. this information is based upon a
Jul 10, 20077.521NONO
CVE-2006-2066MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitra
Apr 27, 20064.321NOYES
CVE-2006-3554HIGH
Directory traversal vulnerability in index.php in MKPortal 1.0.1 Final allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the
Jul 13, 20067.520NONO
CVE-2007-0192HIGH
Cross-site request forgery (CSRF) vulnerability in the save_main operation in the ad_perms section in admin.php in MKPortal allows remote attackers to modify privilege settings, as
Jan 12, 20077.519NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
54%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown13 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown13 (100.0%)
User Interaction
None0 (0.0%)
Unknown13 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown13 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
46.2% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mkportal.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mkportal — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mkportal's Products

View all 1 CNAs →

Top CWEs