Mywebland's vulnerability footprint centers on a modestly sized portfolio of web-based content-management and analytics applications including Mybloggie, MyEvent, and related blog and statistics platforms. While the product line is focused, these applications occupy a prominent position in the vulnerability landscape, likely reflecting their wide deployment across hosted and self-hosted blogging and event-management services. The recurring weakness classes—SQL injection, cross-site request forgery, code injection, and sensitive information exposure—are characteristic of web application input-handling and output-encoding challenges endemic to this category of platform. Notably, vulnerabilities affecting this vendor demonstrate a very high tendency to acquire public exploit code, making patch cycles and access controls material to operational security even where severity does not reach critical thresholds. Current exploitation activity, KEV status, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mywebland over time
Signals from CVEs in this vendor scope (35 CVEs).
35 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4040HIGH PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path para | Aug 9, 2006 | 7.5 | 32 | NO | YES |
CVE-2007-3194CRITICAL Multiple PHP remote file inclusion vulnerabilities in myBloggie 2.1.5 allow remote attackers to execute arbitrary PHP code via a URL in the bloggie_root_path parameter to (1) confi | Jun 12, 2007 | 9.8 | 30 | NO | NO |
CVE-2008-4644HIGH hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For HTTP header. | Oct 22, 2008 | 7.5 | 29 | NO | YES |
CVE-2008-4628HIGH SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL commands via the post_id parameter. | Oct 21, 2008 | 7.5 | 29 | NO | YES |
CVE-2006-4163HIGH PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fna | Aug 16, 2006 | 7.5 | 29 | NO | YES |
CVE-2005-1500HIGH Multiple SQL injection vulnerabilities in myBloggie 2.1.1 allow remote attackers to execute arbitrary SQL commands via (1) the keyword parameter in search.php; or (2) the date_no p | May 11, 2005 | 7.5 | 29 | NO | YES |
CVE-2008-5004HIGH SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbitrary SQL commands via a crafted cookie. | Nov 10, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4650HIGH SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands via the eventdate parameter. | Oct 22, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-4643HIGH SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands via the sortby parameter. | Oct 22, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-3003HIGH Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php | Jun 4, 2007 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (35 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mywebland.
Media articles that mention a CVE ID that affects a product developed by Mywebland — matched by CVE ID, not by vendor name.