Phphq maintains a narrow portfolio of PHP-based applications including Phshoutbox and PhUploader, components typically embedded in web hosting and content-management contexts. The vendor's vulnerability signals center on authentication and access-control weaknesses characteristic of user-facing web components. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phphq over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4527HIGH Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: th | Aug 25, 2007 | 7.5 | 29 | NO | YES |
CVE-2008-1971HIGH phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain privileges by setting the (1) phadmin cookie to admin.php, or | Apr 27, 2008 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phphq.
Media articles that mention a CVE ID that affects a product developed by Phphq — matched by CVE ID, not by vendor name.