Npds maintains a focused line of web content management and portal software, with its vulnerability profile concentrated in the core Npds and Revolution products. The durable signal centers on application-layer weaknesses recurring across input validation, cross-site scripting, SQL injection, and sensitive-data exposure—characteristic of web-facing systems where trust boundaries and data-handling practices are critical attack surfaces. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Npds over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-1400HIGH SQL injection vulnerability in search.php in NPDS Revolution 13 allows remote attackers to execute arbitrary SQL commands via the query parameter. | Feb 3, 2015 | 7.5 | 28 | NO | YES |
CVE-2005-1637HIGH Multiple SQL injection vulnerabilities in NPDS 4.8 and 5.0 allow remote attackers to execute arbitrary SQL commands via the thold parameter to (1) comments.php or (2) pollcomments. | May 17, 2005 | 7.5 | 28 | NO | YES |
CVE-2007-2537MEDIUM Multiple SQL injection vulnerabilities in mainfile.php in NPDS 5.10 and earlier allow remote authenticated users to execute arbitrary SQL commands via a (1) nickname or (2) Id in a | May 9, 2007 | 6.5 | 25 | NO | YES |
CVE-2002-1804MEDIUM Cross-site scripting (XSS) vulnerability in NPDS 4.8 allows remote attackers to inject arbitrary web script or HTML via Javascript in an IMG tag. | Dec 31, 2002 | 4.3 | 21 | NO | YES |
CVE-2006-2951MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.10 and earlier allow remote attackers to inject arbitrary web script and HTML via the (1) | Jun 12, 2006 | 6.8 | 18 | NO | NO |
CVE-2006-2950MEDIUM Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) header.php, (2) contact.php, or (3) forum_exte | Jun 12, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Npds.
Media articles that mention a CVE ID that affects a product developed by Npds — matched by CVE ID, not by vendor name.