Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpauction

First CVE: Mar 20, 2008Active for: 18 yearsTotal CVEs: 4

Phpauction is a PHP-based auction platform with a compact product footprint centered on its core phpauction and phpauction_gpl offerings. The disclosed vulnerabilities cluster around web-application input handling, chiefly code injection, SQL injection, and exposure of sensitive information, reflecting the interpretation and database-query risks inherent to dynamically scripted e-commerce systems. Live severity, exploitation, and current exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpauction over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 2008
18 years ago
Most Recent CVE
Aug 19, 2009
6,183 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-1416MEDIUM
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to (1) conver
Mar 20, 20086.847NOYES
CVE-2008-7000HIGH
PHP remote file inclusion vulnerability in index.php in PHPAuction 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: this might be re
Aug 19, 20097.528NOYES
CVE-2008-2900HIGH
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
Jun 27, 20087.528NOYES
CVE-2008-6999MEDIUM
phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo funct
Aug 19, 20095.017NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown4 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown4 (100.0%)
User Interaction
None0 (0.0%)
Unknown4 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown4 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
75.0% of CVEs· 85th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpauction.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpauction — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpauction's Products

View all 1 CNAs →

Top CWEs