Phpcollab is a modestly deployed project-management and collaboration platform whose vulnerability profile centers on its web application and input-handling layer. The recurring exposure involves SQL injection, OS command injection, and unrestricted file upload weaknesses, patterns typical of server-side web applications with insufficient input validation and access controls. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpcollab over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-6090HIGH Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with | Oct 3, 2017 | 8.8 | 93 | NO | YES |
CVE-2017-6089CRITICAL SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) project or id parameters to topics/deletetopics.php | Oct 3, 2017 | 9.8 | 43 | NO | YES |
CVE-2006-1495HIGH SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL c | Mar 30, 2006 | 7.5 | 32 | NO | YES |
CVE-2017-15907CRITICAL SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php. | Oct 26, 2017 | 9.8 | 28 | NO | NO |
CVE-2008-4305HIGH Static code injection vulnerability in installation/setup.php in phpCollab 2.5 rc3 and earlier allows remote authenticated administrators to inject arbitrary PHP code into include/ | Dec 23, 2008 | 9.0 | 25 | NO | NO |
CVE-2008-4304HIGH general/login.php in phpCollab 2.5 rc3 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified input related to the SSL_CLIENT_CER | Dec 23, 2008 | 10.0 | 25 | NO | NO |
CVE-2011-3772MEDIUM phpCollab 2.5 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated | Sep 24, 2011 | 5.0 | 18 | NO | NO |
CVE-2008-4303MEDIUM Multiple SQL injection vulnerabilities in phpCollab 2.5 rc3, 2.4, and earlier allow remote attackers to execute arbitrary SQL commands via the loginForm parameter to general/login. | Dec 23, 2008 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpcollab.
Media articles that mention a CVE ID that affects a product developed by Phpcollab — matched by CVE ID, not by vendor name.