Phpizabi is a niche PHP-based application with a focused vulnerability footprint centered on input-handling and information-exposure issues such as cross-site scripting, path traversal, improper input validation, and unintended disclosure of sensitive data. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpizabi over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3239HIGH Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP1, when register_globals is enabled, allows remote attackers | Jul 21, 2008 | 9.3 | 36 | NO | YES |
CVE-2008-3723MEDIUM Directory traversal vulnerability in index.php in PHPizabi 0.848b C1 HFP3 allows remote authenticated administrators to read arbitrary files via (1) a .. (dot dot), (2) a URL, or p | Aug 20, 2008 | 6.3 | 26 | NO | YES |
CVE-2008-2018MEDIUM The AssignUser function in template.class.php in PHPizabi 0.848b C1 HFP3 performs unsafe macro expansions on strings delimited by '{' and '}' characters, which allows remote authen | Apr 30, 2008 | 4.0 | 26 | NO | YES |
CVE-2008-3735MEDIUM Cross-site scripting (XSS) vulnerability in index.php in PHPizabi before 848 Core HotFix Pack 3 allows remote attackers to inject arbitrary web script or HTML via the query paramet | Aug 20, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpizabi.
Media articles that mention a CVE ID that affects a product developed by Phpizabi — matched by CVE ID, not by vendor name.