PHP Nuke is a content management system and portal framework that has accumulated a moderate disclosure history centered on its modular plugin architecture, where recurring vulnerabilities affect components such as the Sections, Advanced Classifieds, AutoHTML, and Downloads modules. The durable weakness signal across this vendor is SQL injection, reflecting the prevalence of unfiltered database queries within its user-contributed and third-party module ecosystem, and vulnerabilities in this class have a moderate tendency to acquire public exploit code. Defenders deploying PHP Nuke installations should prioritize inventory and patching of enabled modules, since the framework's modular design distributes risk across third-party contributions rather than core binaries alone, and the SQL injection pattern points to input validation as a consistent remediation focus. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Nuke over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1842HIGH Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php. | Dec 31, 2004 | 8.8 | 38 | NO | YES |
CVE-2008-1220HIGH SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules. | Mar 10, 2008 | 7.5 | 34 | NO | YES |
CVE-2008-4767HIGH Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3 | Oct 28, 2008 | 9.0 | 33 | NO | YES |
CVE-2008-0881HIGH SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar acti | Feb 21, 2008 | 7.5 | 33 | NO | YES |
CVE-2007-1626HIGH PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | Mar 23, 2007 | 9.3 | 33 | NO | YES |
CVE-2010-5083HIGH SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php | Feb 14, 2012 | 7.5 | 32 | NO | YES |
CVE-2001-0899HIGH Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. | Nov 16, 2001 | 7.5 | 32 | NO | YES |
CVE-2008-1053HIGH Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticl | Feb 27, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-0922HIGH SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modu | Feb 22, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-0906HIGH SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation. | Feb 22, 2008 | 7.5 | 30 | NO | YES |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Nuke.
Media articles that mention a CVE ID that affects a product developed by Php Nuke — matched by CVE ID, not by vendor name.