Myphpnuke is a content-management and gallery system with a narrow product footprint but persistent presence in PHP-driven web applications, where its vulnerabilities cluster around web-application input handling. The recurring exposure centers on cross-site scripting and SQL injection flaws characteristic of server-side template and database-query construction, alongside categorization gaps in NVD placeholder entries. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Myphpnuke over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4092HIGH SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the artid parameter. | Sep 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4088HIGH SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitrary SQL commands via the sid parameter. | Sep 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2006-6795HIGH PHP remote file inclusion vulnerability in gallery/displayCategory.php in the My_eGallery 2.5.6 module in myPHPNuke (MPN) allows remote attackers to execute arbitrary PHP code via | Dec 28, 2006 | 7.5 | 28 | NO | YES |
CVE-2008-4089MEDIUM Cross-site scripting (XSS) vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | Sep 15, 2008 | 4.3 | 22 | NO | YES |
CVE-2006-0923MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter i | Feb 28, 2006 | 4.3 | 21 | NO | YES |
CVE-2003-1372MEDIUM Cross-site scripting (XSS) vulnerability in links.php script in myPHPNuke 1.8.8, and possibly earlier versions, allows remote attackers to inject arbitrary HTML and web script via | Dec 31, 2003 | 4.3 | 21 | NO | YES |
CVE-2002-1913MEDIUM phptonuke.php in myPHPNuke 1.8.8 allows remote attackers to read arbitrary files via a full pathname in the filnavn variable. | Dec 31, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Myphpnuke.
Media articles that mention a CVE ID that affects a product developed by Myphpnuke — matched by CVE ID, not by vendor name.