Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Php Stats

First CVE: Mar 24, 2008Active for: 18 yearsTotal CVEs: 13

PHP Stats is a modestly represented analytics and statistics product that occupies a focused vulnerability footprint around its single product line. The recurring disclosures reflect the input-handling and data-processing demands typical of web analytics tools. Current severity, exploitation status, and exposure details are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 93% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 52% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Php Stats over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 9, 2006
20 years ago
Most Recent CVE
Feb 20, 2009
6,365 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-7173HIGH
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to execute arbitrary PHP code via a crafted option_new[report_w_da
Mar 20, 200710.036NOYES
CVE-2007-5452HIGH
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arbitrary SQL commands via the (1) ip or (2) t parameter.
Oct 14, 200710.035NOYES
CVE-2007-5453HIGH
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitrary code by writing PHP sequences to the php-stats-options r
Oct 14, 20078.532NOYES
CVE-2006-7172HIGH
Multiple SQL injection vulnerabilities in php-stats.recphp.php in PHP-Stats 0.1.9.1b and earlier allow remote attackers to execute arbitrary code via a leading dotted-quad IP addre
Mar 20, 20077.528NOYES
CVE-2006-1085HIGH
admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileges, and execute arbitrary PHP code by modifying the option[a
Mar 9, 200610.025NONO
CVE-2008-0125MEDIUM
Cross-site scripting (XSS) vulnerability in phpstats.php in Michael Wagner phpstats 0.1 alpha allows remote attackers to inject arbitrary web script or HTML via the baseDir paramet
Mar 24, 20084.323NOYES
CVE-2008-6212MEDIUM
Cross-site scripting (XSS) vulnerability in admin.php in Php-Stats 0.1.9.1 allows remote attackers to inject arbitrary web script or HTML via the (1) sel_mese and (2) sel_anno para
Feb 20, 20094.321NOYES
CVE-2007-4917MEDIUM
Cross-site scripting (XSS) vulnerability in tracking.php in PHP-Stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the ip parameter in an online actio
Sep 17, 20074.321NOYES
CVE-2007-4334MEDIUM
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary web script or HTML via the IP parameter.
Aug 14, 20074.321NOYES
CVE-2006-1083HIGH
Multiple directory traversal vulnerabilities in PHP-Stats 0.1.9.1 and earlier allow remote attackers to read and possibly execute arbitrary files via a .. (dot dot) in the (1) opti
Mar 9, 20067.520NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
54%
Severity distribution among all CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown13 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown13 (100.0%)
User Interaction
None0 (0.0%)
Unknown13 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown13 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
61.5% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Php Stats.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Php Stats — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Php Stats's Products

View all 1 CNAs →

Top CWEs