Mysimplenews maintains a focused news-aggregation application where vulnerabilities have centered on code-injection issues, reflecting risks inherent to dynamic content handling and user input processing in web-driven systems. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mysimplenews over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2143HIGH The admin.html file in MySimple News 1.0 stores its administrative password in plaintext, which allows remote attackers to gain unauthorized access to the web server by viewing the | Dec 31, 2002 | 7.5 | 30 | NO | YES |
CVE-2002-2319HIGH Static code injection vulnerability in users.php in MySimpleNews allows remote attackers to inject arbitrary PHP code and HTML via the (1) LOGIN, (2) DATA, and (3) MESS parameters, | Dec 31, 2002 | 7.5 | 28 | NO | YES |
CVE-2002-2320HIGH MySimpleNews 1.0 allows remote attackers to delete arbitrary email messages via a direct request to vider.php3. | Dec 31, 2002 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mysimplenews.
Media articles that mention a CVE ID that affects a product developed by Mysimplenews — matched by CVE ID, not by vendor name.