Phparanoid is a narrowly scoped PHP-based security tool whose disclosed vulnerabilities center on its core product and reflect application-layer input-handling weaknesses, principally cross-site request forgery. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phparanoid over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5758MEDIUM Cross-site request forgery (CSRF) vulnerability in PHParanoid before 0.5 allows remote attackers to perform unspecified actions as authenticated users via unknown vectors related t | Dec 30, 2008 | 6.8 | 19 | NO | NO |
CVE-2008-5672MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in PHParanoid before 0.4 allow remote attackers to hijack the authentication of arbitrary users for requests that use (1) | Dec 19, 2008 | 6.8 | 18 | NO | NO |
CVE-2008-5673MEDIUM PHParanoid before 0.4 does not properly restrict access to the members area by unauthenticated users, which has unknown impact and remote attack vectors. | Dec 19, 2008 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phparanoid.
Media articles that mention a CVE ID that affects a product developed by Phparanoid — matched by CVE ID, not by vendor name.