Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Php Arena

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 33
35.2
VTI Score
Medium

PHP Arena maintains a small collection of open-source web applications focused on content management and community features, including products such as PAFileDB, PAFAQ, PABugs, PANews, and PABox. Despite the narrow product scope, these applications have attracted a recurring pattern of public exploit tooling availability, reflecting their historical deployment across self-hosted web environments. The vulnerability disclosures cluster around general application-layer weaknesses rather than a specific, well-defined class, which is typical of legacy or feature-rich web applications where attack surface and input handling evolve across versions. Defenders should approach this vendor's advisories with attention to the public exploit landscape and tailor patching to their deployed instances; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 97% of tracked vendors
1.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
5.8
Avg CVSS Score
Higher Avg CVSS Score than 25% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Php Arena over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Aug 8, 2007
6,925 days ago

Products(6 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2005-2000HIGH
Multiple SQL injection vulnerabilities in paFileDB 3.1 and earlier allow remote attackers to execute arbitrary SQL commands via the formname parameter (1) in the login form, (2) in
Jun 15, 20057.535NOYES
CVE-2005-2012HIGH
Multiple SQL injection vulnerabilities in login in paFAQ 1.0 Beta 4 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username or (2) i
Jun 20, 20057.533NOYES
CVE-2005-2011MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in paFAQ 1.0 Beta 4 allow remote attackers to inject arbitrary web script or HTML, as demonstrated via the id parameter in a Que
Jun 20, 20054.331NOYES
CVE-2006-5079HIGH
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pat
Sep 29, 20067.529NOYES
CVE-2006-2361HIGH
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as used with phpBB, allows remote attackers to execute arbitrary
May 15, 20067.529NOYES
CVE-2007-4183HIGH
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the cid parameter to index.php.
Aug 8, 20077.528NOYES
CVE-2007-3808HIGH
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL commands via the categories[] parameter in a search action to in
Jul 17, 20077.528NOYES
CVE-2005-4329HIGH
SQL injection vulnerability in pafiledb.php in PHP Arena paFileDB Extreme Edition RC 5 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) newsid and
Dec 17, 20057.528NOYES
CVE-2005-0781HIGH
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers to execute arbitrary SQL commands via the start parameter to
May 2, 20057.528NOYES
CVE-2006-2209MEDIUM
Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add
May 5, 20066.425NOYES
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
67%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown33 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown33 (100.0%)
User Interaction
None0 (0.0%)
Unknown33 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown33 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
18 CVEs
54.5% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Php Arena.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Php Arena — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Php Arena's Products

View all 1 CNAs →