PHP Sugar is a narrowly scoped PHP development or utility product with a minimal tracked vulnerability footprint. Current vulnerability details and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Php Sugar over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5211CRITICAL PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | Jan 9, 2018 | 9.8 | 40 | NO | YES |
CVE-2017-15081CRITICAL In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | Oct 24, 2017 | 9.8 | 40 | NO | YES |
CVE-2017-15579CRITICAL In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. | Oct 18, 2017 | 9.8 | 39 | NO | YES |
CVE-2017-15578HIGH In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php. | Oct 18, 2017 | 8.8 | 37 | NO | YES |
CVE-2009-2895HIGH SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter. | Aug 20, 2009 | 7.5 | 29 | NO | YES |
CVE-2021-47915HIGH PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can ex | Feb 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2009-2398MEDIUM Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter. | Jul 9, 2009 | 5.0 | 23 | NO | YES |
CVE-2021-47912MEDIUM PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts th | Feb 1, 2026 | 6.4 | 22 | NO | NO |
CVE-2021-47914MEDIUM PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script co | Feb 1, 2026 | 6.4 | 21 | NO | NO |
CVE-2021-47913MEDIUM PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSI | Feb 1, 2026 | 6.4 | 21 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Php Sugar.
Media articles that mention a CVE ID that affects a product developed by Php Sugar — matched by CVE ID, not by vendor name.