Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpfox

First CVE: May 27, 2006Active for: 20 yearsTotal CVEs: 10
36.4
VTI Score
Medium

Phpfox is a narrowly scoped social networking and community platform whose vulnerability footprint concentrates in its single flagship product and recurs through web-application input-handling weaknesses including cross-site scripting, SQL injection, and cross-site request forgery, alongside deserialization flaws typical of dynamic web frameworks. Vulnerabilities affecting the vendor have a marked tendency toward public exploit availability and reach a meaningful share of serious severity outcomes. Live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
10
Total CVEs
More Total CVEs than 92% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.4
Avg CVSS Score
Higher Avg CVSS Score than 39% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpfox over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 27, 2006
20 years ago
Most Recent CVE
Apr 22, 2024
823 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2013-5121HIGH
SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/.
Aug 14, 20137.534NOYES
CVE-2023-46817CRITICAL
An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unseriali
Nov 3, 20239.830NONO
CVE-2013-7196MEDIUM
static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request wit
Apr 18, 20145.529NOYES
CVE-2013-5120HIGH
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.
Aug 14, 20137.528NOYES
CVE-2022-34560HIGH
A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.
Apr 22, 20247.121NONO
CVE-2013-7195MEDIUM
PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specifies the ID for the publication.
Apr 18, 20145.520NONO
CVE-2022-34562MEDIUM
A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the status box.
Apr 22, 20246.119NONO
CVE-2009-0969MEDIUM
Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authentication of administrators for re
Mar 19, 20096.819NONO
CVE-2022-34561MEDIUM
A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the video description para
Apr 22, 20244.316NONO
CVE-2006-2631MEDIUM
phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the phpfox_user parameter.
May 27, 20064.014NONO
View all 10 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products10 CVEs
60%
30%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network4 (40.0%)
Unknown6 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (40.0%)
High0 (0.0%)
Unknown6 (60.0%)
User Interaction
None1 (10.0%)
Unknown6 (60.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (40.0%)
Unknown6 (60.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
30.0% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpfox.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpfox — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpfox's Products

View all 1 CNAs →

Top CWEs