Newsphp is a modestly represented content-management and news-publishing platform whose vulnerability profile concentrates on its core product and reflects typical application-layer risks in web-based publishing software. The recurring weakness classes—cross-site scripting, SQL injection, and input-handling issues—are characteristic of dynamic web applications, and public exploit code has frequently become available for disclosed flaws in this product. Defenders should prioritize input-validation and parameterized-query practices when deploying or maintaining this software; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Newsphp over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3359HIGH Multiple SQL injection vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) topmenuitem, an | Jul 6, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0413HIGH Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limi | Jan 25, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-3358MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) ca | Jul 6, 2006 | 6.8 | 26 | NO | YES |
CVE-2004-2689HIGH NewsPHP allows remote attackers to gain unauthorized administrative access by setting a cookie to the "autorized=admin; root=admin" value. | Dec 31, 2004 | 10.0 | 25 | NO | NO |
CVE-2004-2690HIGH Unrestricted file upload vulnerability in the Administration Panel for NewsPHP allows remote authenticated administrators to upload and execute arbitrary code instead of video file | Dec 31, 2004 | 8.5 | 22 | NO | NO |
CVE-2003-0754HIGH nphpd.php in newsPHP 216 and earlier allows remote attackers to bypass authentication via an HTTP request with a modified nphp_users array, which is used for authentication. | Oct 20, 2003 | 7.5 | 20 | NO | NO |
CVE-2003-0753MEDIUM nphpd.php in newsPHP 216 and earlier allows remote attackers to read arbitrary files via a full pathname to the target file in the nphp_config[LangFile] parameter. | Oct 20, 2003 | 5.0 | 15 | NO | NO |
CVE-2004-2688MEDIUM Cross-site scripting (XSS) vulnerability in index.php in NewsPHP allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. NOTE: this issue might ov | Dec 31, 2004 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Newsphp.
Media articles that mention a CVE ID that affects a product developed by Newsphp — matched by CVE ID, not by vendor name.