Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpgedview

First CVE: Jan 20, 2004Active for: 23 yearsTotal CVEs: 17
49.4
VTI Score
High

Phpgedview is a genealogy management application with a modest but established vulnerability footprint concentrated in its single product. The exposure clusters around web-application input-handling and access-control weaknesses—including cross-site scripting, path traversal, and information disclosure—that are characteristic of server-side PHP applications; vulnerabilities here frequently acquire public exploit code. Defenders tracking this application should prioritize patches for internet-facing instances and validate access controls around sensitive genealogical records; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
3.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpgedview over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 20, 2004
22 years ago
Most Recent CVE
Sep 24, 2011
5,417 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0030CRITICAL
PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitra
Jan 20, 20049.837NOYES
CVE-2011-0405MEDIUM
Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files
Jan 11, 20116.832NOYES
CVE-2005-4468HIGH
PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY pa
Dec 22, 20057.531NOYES
CVE-2004-0128HIGH
PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the
Mar 3, 20047.531NOYES
CVE-2004-0032MEDIUM
Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter.
Jan 20, 20046.827NOYES
CVE-2008-2064HIGH
Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGe
May 2, 200810.025NONO
CVE-2005-4467MEDIUM
Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_BA
Dec 22, 20055.024NOYES
CVE-2004-0033MEDIUM
admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command.
Jan 20, 20045.023NOYES
CVE-2004-0067MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php,
Feb 17, 20044.322NOYES
CVE-2005-4469HIGH
Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php,
Dec 22, 20057.520NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
53%
41%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network1 (5.9%)
Unknown16 (94.1%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (5.9%)
High0 (0.0%)
Unknown16 (94.1%)
User Interaction
None1 (5.9%)
Unknown16 (94.1%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (5.9%)
Unknown16 (94.1%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
47.1% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgedview.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpgedview — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpgedview's Products

View all 1 CNAs →

Top CWEs