Phpkit is a modestly represented web application framework with a concentrated vulnerability footprint centered on its single namesake product. The vendor's exposure recurs through a consistent pattern of input-handling and code-generation weaknesses including cross-site scripting, SQL injection, cross-site request forgery, and code injection, characteristic of web-facing PHP applications where boundary validation and output encoding are critical. While the vulnerability count is modest relative to large platform vendors, the weakness classes present carry a meaningful attack surface in web-deployment contexts, and public exploit code has been developed for many of these disclosures. Defenders operating Phpkit instances should prioritize patching, implement input validation and output encoding discipline, and restrict access to administrative interfaces; current severity, exploitation activity, and CVE details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpkit over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10758HIGH PHPKIT 1.6.6 allows arbitrary File Upload, as demonstrated by a .php file to pkinc/admin/mediaarchive.php and pkinc/func/default.php via the image_name parameter. | May 24, 2019 | 8.8 | 28 | NO | NO |
CVE-2007-6134HIGH SQL injection vulnerability in pkinc/public/article.php in PHPKIT 1.6.4pl1 allows remote attackers to execute arbitrary SQL commands via the contentid parameter in an article actio | Nov 27, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-0179HIGH SQL injection vulnerability in comment.php in PHPKIT 1.6.1 R2 allows remote attackers to execute arbitrary SQL commands via the subid parameter. | Jan 11, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-2683HIGH Multiple SQL injection vulnerabilities in PHPKit 1.6.1 allow remote attackers to execute arbitrary SQL commands via the (1) letter parameter to login/member.php or (2) im_receiver | Aug 23, 2005 | 7.5 | 28 | NO | YES |
CVE-2003-1187MEDIUM Cross-site scripting (XSS) vulnerability in include.php in PHPKIT 1.6.02 and 1.6.03 allows remote attackers to inject arbitrary web script or HTML via the contact_email parameter. | Nov 2, 2003 | 6.8 | 28 | NO | YES |
CVE-2004-1537MEDIUM Cross-site scripting (XSS) vulnerability in popup.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary web script via the img parameter. | Dec 31, 2004 | 4.3 | 26 | NO | YES |
CVE-2006-1773MEDIUM SQL injection vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier allows remote attackers to execute arbitrary SQL commands via the contentid parameter, possibly inv | Apr 13, 2006 | 6.4 | 25 | NO | YES |
CVE-2004-1538HIGH SQL injection vulnerability in include.php in PHPKIT 1.6.03 through 1.6.1 allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 31, 2004 | 7.5 | 24 | NO | NO |
CVE-2006-0786MEDIUM Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include at | Feb 19, 2006 | 5.1 | 23 | NO | YES |
CVE-2005-3553HIGH Multiple SQL injection vulnerabilities in include.php in PHPKIT 1.6.1 R2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in conjunctio | Nov 16, 2005 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpkit.
Media articles that mention a CVE ID that affects a product developed by Phpkit — matched by CVE ID, not by vendor name.