Phpmyfactures is a narrowly scoped invoicing and billing application with a focused vulnerability footprint centered on the eponymous product. The observed exposure reflects input-handling and web-application-layer weaknesses typical of self-hosted accounting software; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpmyfactures over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3092HIGH PhpMyFactures 1.2 and earlier allows remote attackers to bypass authentication and modify data via direct requests with modified parameters to (1) /tva/ajouter_tva.php, (2) /remise | Jun 19, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-3090MEDIUM Multiple SQL injection vulnerabilities in PhpMyFactures 1.0, and possibly 1.2 and earlier, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands | Jun 19, 2006 | 5.1 | 15 | NO | NO |
CVE-2006-3091MEDIUM PhpMyFactures 1.0, and possibly 1.2 and earlier, allows remote attackers to obtain the installation path via a direct request to (1) /verif.php, (2) /inc/footer.php, and (3) /remis | Jun 19, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-3089MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in PhpMyFactures 1.0, and possibly 1.2 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) pr | Jun 19, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpmyfactures.
Media articles that mention a CVE ID that affects a product developed by Phpmyfactures — matched by CVE ID, not by vendor name.