Phpgedview is a genealogy management application with a modest but established vulnerability footprint concentrated in its single product. The exposure clusters around web-application input-handling and access-control weaknesses—including cross-site scripting, path traversal, and information disclosure—that are characteristic of server-side PHP applications; vulnerabilities here frequently acquire public exploit code. Defenders tracking this application should prioritize patches for internet-facing instances and validate access controls around sensitive genealogical records; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpgedview over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0030CRITICAL PHP remote file inclusion vulnerability in (1) functions.php, (2) authentication_index.php, and (3) config_gedcom.php for PHPGEDVIEW 2.61 allows remote attackers to execute arbitra | Jan 20, 2004 | 9.8 | 37 | NO | YES |
CVE-2011-0405MEDIUM Directory traversal vulnerability in module.php in PhpGedView 4.2.3 and possibly other versions, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files | Jan 11, 2011 | 6.8 | 32 | NO | YES |
CVE-2005-4468HIGH PHP remote file include vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to execute arbitrary code via a URL in the PGV_BASE_DIRECTORY pa | Dec 22, 2005 | 7.5 | 31 | NO | YES |
CVE-2004-0128HIGH PHP remote file inclusion vulnerability in the GEDCOM configuration script for phpGedView 2.65.1 and earlier allows remote attackers to execute arbitrary PHP code by modifying the | Mar 3, 2004 | 7.5 | 31 | NO | YES |
CVE-2004-0032MEDIUM Cross-site scripting (XSS) vulnerability in search.php in PHPGEDVIEW 2.61 allows remote attackers to inject arbitrary HTML and web script via the firstname parameter. | Jan 20, 2004 | 6.8 | 27 | NO | YES |
CVE-2008-2064HIGH Multiple unspecified vulnerabilities in PhpGedView before 4.1.5 have unknown impact and attack vectors related to "a fundamental design flaw in the interface (API) to connect phpGe | May 2, 2008 | 10.0 | 25 | NO | NO |
CVE-2005-4467MEDIUM Directory traversal vulnerability in help_text_vars.php in PHPGedView 3.3.7 and earlier allows remote attackers to read and include arbitrary files via a .. (dot dot) in the PGV_BA | Dec 22, 2005 | 5.0 | 24 | NO | YES |
CVE-2004-0033MEDIUM admin.php in PHPGEDVIEW 2.61 allows remote attackers to obtain sensitive information via an action parameter with a phpinfo command. | Jan 20, 2004 | 5.0 | 23 | NO | YES |
CVE-2004-0067MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpGedView before 2.65 allow remote attackers to inject arbitrary HTML or web script via (1) descendancy.php, (2) index.php, | Feb 17, 2004 | 4.3 | 22 | NO | YES |
CVE-2005-4469HIGH Multiple direct static code injection vulnerabilities in PHPGedView 3.3.7 and earlier allow remote attackers to execute arbitrary PHP code via (1) the username field in login.php, | Dec 22, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpgedview.
Media articles that mention a CVE ID that affects a product developed by Phpgedview — matched by CVE ID, not by vendor name.