Phpfox is a narrowly scoped social networking and community platform whose vulnerability footprint concentrates in its single flagship product and recurs through web-application input-handling weaknesses including cross-site scripting, SQL injection, and cross-site request forgery, alongside deserialization flaws typical of dynamic web frameworks. Vulnerabilities affecting the vendor have a marked tendency toward public exploit availability and reach a meaningful share of serious severity outcomes. Live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpfox over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5121HIGH SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/. | Aug 14, 2013 | 7.5 | 34 | NO | YES |
CVE-2023-46817CRITICAL An issue was discovered in phpFox before 4.8.14. The url request parameter passed to the /core/redirect route is not properly sanitized before being used in a call to the unseriali | Nov 3, 2023 | 9.8 | 30 | NO | NO |
CVE-2013-7196MEDIUM static/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment on a private publication via a request wit | Apr 18, 2014 | 5.5 | 29 | NO | YES |
CVE-2013-5120HIGH SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/. | Aug 14, 2013 | 7.5 | 28 | NO | YES |
CVE-2022-34560HIGH A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter. | Apr 22, 2024 | 7.1 | 21 | NO | NO |
CVE-2013-7195MEDIUM PHPFox 3.7.3 and 3.7.4 allows remote authenticated users to bypass intended "Only Me" restrictions and "like" a publication via a request that specifies the ID for the publication. | Apr 18, 2014 | 5.5 | 20 | NO | NO |
CVE-2022-34562MEDIUM A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the status box. | Apr 22, 2024 | 6.1 | 19 | NO | NO |
CVE-2009-0969MEDIUM Cross-site request forgery (CSRF) vulnerability in account/settings/account/index.php in phpFoX 1.6.21 allows remote attackers to hijack the authentication of administrators for re | Mar 19, 2009 | 6.8 | 19 | NO | NO |
CVE-2022-34561MEDIUM A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the video description para | Apr 22, 2024 | 4.3 | 16 | NO | NO |
CVE-2006-2631MEDIUM phpFoX allows remote authenticated users to modify arbitrary accounts via a modified NATIO cookie value, possibly the phpfox_user parameter. | May 27, 2006 | 4.0 | 14 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpfox.
Media articles that mention a CVE ID that affects a product developed by Phpfox — matched by CVE ID, not by vendor name.