Phpf1 develops a narrow set of web-based utilities, primarily Max's Guestbook and Max's Image Uploader, where the durable signal centers on application-layer input-handling vulnerabilities such as cross-site scripting. Treat this as a compact vendor profile rather than a broad trend line; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpf1 over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-0390MEDIUM Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or | Jan 26, 2010 | 6.8 | 27 | NO | YES |
CVE-2008-6359MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Max's Guestbook allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) email, and (3) message | Mar 2, 2009 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpf1.
Media articles that mention a CVE ID that affects a product developed by Phpf1 — matched by CVE ID, not by vendor name.