PHP-Nuke is a content management system and portal framework whose vulnerability footprint concentrates in a modestly sized but prominently deployed codebase spanning the core platform and community modules such as sections, web links, and chat functionality. The exposure recurs through application-layer input-handling weakness classes—SQL injection, cross-site scripting, cross-site request forgery, and sensitive information disclosure—that are characteristic of server-side PHP applications built around user-supplied content and administrative forms. Notably, this vendor's vulnerabilities frequently acquire public exploit code, reflecting both the open-source nature of the platform and its historical appeal as a target for commodity web attacks and defacement campaigns. Defenders deploying PHP-Nuke should treat input validation and output encoding as critical hardening areas and prioritize timely patching of the core framework and contributed modules; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpnuke over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1842HIGH Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administrative privileges via an img tag with a URL to admin.php. | Dec 31, 2004 | 8.8 | 38 | NO | YES |
CVE-2008-1220HIGH SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the roomid parameter in an index action to modules. | Mar 10, 2008 | 7.5 | 34 | NO | YES |
CVE-2008-4767HIGH Unrestricted file upload vulnerability in the DownloadsPlus module in PHP-Nuke allows remote attackers to execute arbitrary code by uploading a file with (1) .htm, (2) .html, or (3 | Oct 28, 2008 | 9.0 | 33 | NO | YES |
CVE-2008-0881HIGH SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar acti | Feb 21, 2008 | 7.5 | 33 | NO | YES |
CVE-2007-1626HIGH PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. | Mar 23, 2007 | 9.3 | 33 | NO | YES |
CVE-2010-5083HIGH SQL injection vulnerability in the Web_Links module for PHP-Nuke 8.0 allows remote attackers to execute arbitrary SQL commands via the url parameter in an Add action to modules.php | Feb 14, 2012 | 7.5 | 32 | NO | YES |
CVE-2001-0899HIGH Network Tools 0.2 for PHP-Nuke allows remote attackers to execute commands on the server via shell metacharacters in the $hostinput variable. | Nov 16, 2001 | 7.5 | 32 | NO | YES |
CVE-2008-1053HIGH Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitrary SQL commands via the artid parameter in a (1) viewarticl | Feb 27, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-0922HIGH SQL injection vulnerability in the Manuales 0.1 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the cid parameter in a viewdownload action to modu | Feb 22, 2008 | 7.5 | 30 | NO | YES |
CVE-2008-0906HIGH SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the artid parameter in a viewarticle operation. | Feb 22, 2008 | 7.5 | 30 | NO | YES |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpnuke.
Media articles that mention a CVE ID that affects a product developed by Phpnuke — matched by CVE ID, not by vendor name.