PHP Kobo's vulnerability profile centers on a pair of free, web-based content-management and form-handling applications, with the durable signal rooted in application-layer input-handling weaknesses including cross-site scripting and cross-site request forgery. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Kobo over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41449CRITICAL An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | Sep 27, 2023 | 9.8 | 32 | NO | NO |
CVE-2010-1058MEDIUM Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execu | Mar 23, 2010 | 6.8 | 30 | NO | YES |
CVE-2010-1062MEDIUM Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include | Mar 23, 2010 | 6.8 | 28 | NO | YES |
CVE-2010-1060MEDIUM Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary | Mar 23, 2010 | 6.8 | 28 | NO | YES |
CVE-2010-1057MEDIUM Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitr | Mar 23, 2010 | 6.8 | 27 | NO | YES |
CVE-2023-41452HIGH Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index | Sep 27, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41450HIGH An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | Sep 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2010-1059MEDIUM Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute | Mar 23, 2010 | 6.8 | 21 | NO | NO |
CVE-2023-41447MEDIUM Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.ph | Sep 28, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-41446MEDIUM Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php | Sep 28, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Kobo.
Media articles that mention a CVE ID that affects a product developed by Php Kobo — matched by CVE ID, not by vendor name.