Nucleus Group's vulnerability footprint centers on its Nucleus CMS product, a content-management platform where observed weaknesses cluster around code injection, path traversal, and related input-handling and path-validation issues. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nucleus Group over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-2314MEDIUM PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucleus, when register_globals is enabled, allows remote attacker | Jun 17, 2010 | 6.8 | 30 | NO | YES |
CVE-2006-3136CRITICAL Multiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIBS parameter in (1) path/action.php, and | Jun 22, 2006 | 9.8 | 30 | NO | NO |
CVE-2006-2583MEDIUM PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[D | May 25, 2006 | 5.1 | 25 | NO | YES |
CVE-2004-2056HIGH SQL injection vulnerability in action.php in Nucleus CMS 3.01 allows remote attackers to execute arbitrary SQL statements via the itemid parameter. | Dec 31, 2004 | 7.5 | 19 | NO | NO |
CVE-2009-0929MEDIUM Directory traversal vulnerability in the media manager in Nucleus CMS before 3.40 allows remote attackers to read arbitrary files via unknown vectors. | Mar 17, 2009 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nucleus Group.
Media articles that mention a CVE ID that affects a product developed by Nucleus Group — matched by CVE ID, not by vendor name.