Phpkobo develops a small portfolio of web-based applications including content management, form handling, and utility scripts that are modestly deployed across small business and personal websites. The vendor's disclosures cluster around application-layer input and output handling weaknesses—path traversal, cross-site scripting, code injection, and CSRF—that are typical of legacy PHP codebases, and a meaningful share of these vulnerabilities acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpkobo over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41449CRITICAL An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | Sep 27, 2023 | 9.8 | 32 | NO | NO |
CVE-2010-1058MEDIUM Directory traversal vulnerability in codelib/cfg/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execu | Mar 23, 2010 | 6.8 | 30 | NO | YES |
CVE-2010-1062MEDIUM Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include | Mar 23, 2010 | 6.8 | 28 | NO | YES |
CVE-2010-1060MEDIUM Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Short URL 1.01, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary | Mar 23, 2010 | 6.8 | 28 | NO | YES |
CVE-2010-1057MEDIUM Multiple directory traversal vulnerabilities in Phpkobo AdFreely (aka Ad Board Script) 1.01, when magic_quotes_gpc is disabled, allow remote attackers to include and execute arbitr | Mar 23, 2010 | 6.8 | 27 | NO | YES |
CVE-2023-41452HIGH Cross Site Request Forgery vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the txt parameter in the index | Sep 27, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-41450HIGH An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter. | Sep 28, 2023 | 8.8 | 25 | NO | NO |
CVE-2010-1059MEDIUM Directory traversal vulnerability in staff/app/common.inc.php in Phpkobo Address Book Script 1.09, when magic_quotes_gpc is disabled, allows remote attackers to include and execute | Mar 23, 2010 | 6.8 | 21 | NO | NO |
CVE-2023-41447MEDIUM Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the subcmd parameter in the index.ph | Sep 28, 2023 | 6.1 | 20 | NO | NO |
CVE-2023-41446MEDIUM Cross Site Scripting vulnerability in phpkobo AjaxNewTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted script to the title parameter in the index.php | Sep 28, 2023 | 6.1 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpkobo.
Media articles that mention a CVE ID that affects a product developed by Phpkobo — matched by CVE ID, not by vendor name.