Phpbugtracker Project maintains a narrowly scoped issue-tracking application that, despite its focused scope, has disclosed vulnerabilities that skew strongly toward critical severity and frequently acquire public exploit code. The exposure recurs through classic web-application weakness classes including cross-site scripting, cross-site request forgery, and SQL injection, reflecting the input-handling and session-management demands of a web-based bug-tracking system. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpbugtracker Project over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-2147CRITICAL Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters. | Oct 6, 2017 | 9.8 | 34 | NO | YES |
CVE-2015-2143HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that | Oct 6, 2017 | 8.8 | 31 | NO | YES |
CVE-2015-2142HIGH Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for | Oct 6, 2017 | 8.0 | 29 | NO | YES |
CVE-2015-2146CRITICAL Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, | Oct 6, 2017 | 9.8 | 24 | NO | NO |
CVE-2015-2145MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified paramet | Oct 6, 2017 | 4.8 | 22 | NO | YES |
CVE-2015-2148MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified paramet | Oct 6, 2017 | 4.8 | 15 | NO | NO |
CVE-2015-2144MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) p | Oct 6, 2017 | 4.8 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpbugtracker Project.
Media articles that mention a CVE ID that affects a product developed by Phpbugtracker Project — matched by CVE ID, not by vendor name.