PHP Arena maintains a small collection of open-source web applications focused on content management and community features, including products such as PAFileDB, PAFAQ, PABugs, PANews, and PABox. Despite the narrow product scope, these applications have attracted a recurring pattern of public exploit tooling availability, reflecting their historical deployment across self-hosted web environments. The vulnerability disclosures cluster around general application-layer weaknesses rather than a specific, well-defined class, which is typical of legacy or feature-rich web applications where attack surface and input handling evolve across versions. Defenders should approach this vendor's advisories with attention to the public exploit landscape and tailor patching to their deployed instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Arena over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2000HIGH Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in | Jun 15, 2005 | 7.5 | 35 | NO | YES |
CVE-2005-2012HIGH Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) i | Jun 20, 2005 | 7.5 | 33 | NO | YES |
CVE-2005-2011MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Que | Jun 20, 2005 | 4.3 | 31 | NO | YES |
CVE-2006-5079HIGH PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pat | Sep 29, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-2361HIGH PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary | May 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-4183HIGH SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php. | Aug 8, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3808HIGH SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to in | Jul 17, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-4329HIGH SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and | Dec 17, 2005 | 7.5 | 28 | NO | YES |
CVE-2005-0781HIGH SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to | May 2, 2005 | 7.5 | 28 | NO | YES |
CVE-2006-2209MEDIUM Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add | May 5, 2006 | 6.4 | 25 | NO | YES |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Arena.
Media articles that mention a CVE ID that affects a product developed by Php Arena — matched by CVE ID, not by vendor name.