Phpcaptcha provides a CAPTCHA library focused on the Securimage product, a web-application component for challenge-response verification. Observed vulnerabilities in this vendor concentrate on code-injection weaknesses in the generation and validation logic, a pattern consistent with the parsing and user-input handling inherent to CAPTCHA implementations. Current severity, exploitation activity, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpcaptcha over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-14077MEDIUM HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example | Nov 18, 2017 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpcaptcha.
Media articles that mention a CVE ID that affects a product developed by Phpcaptcha — matched by CVE ID, not by vendor name.