Phpprojekt is a project-management and collaboration application with a modestly scoped vulnerability footprint centered on the single product. The limited historical signal reflects early-era disclosure patterns and broad categorization gaps rather than a complete characterization of its risk profile; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpprojekt over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0451HIGH filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the URL to the code in the lib_path parameter. | Aug 12, 2002 | 7.5 | 37 | NO | YES |
CVE-2006-4609MEDIUM Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attacker | Sep 7, 2006 | 5.1 | 23 | NO | YES |
CVE-2001-0995HIGH PHProjekt before 2.4a allows remote attackers to perform actions as other PHProjekt users by modifying the ID number in an HTTP request to PHProjekt CGI programs. | Aug 31, 2001 | 7.5 | 19 | NO | NO |
CVE-2007-1638MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the check_csrftoken function in lib/lib.inc.php in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote at | Mar 23, 2007 | 6.8 | 18 | NO | NO |
CVE-2007-1639MEDIUM Unrestricted file upload vulnerability in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allows remote authenticated users to upload and execute arbitrary PHP code via a file | Mar 23, 2007 | 4.6 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpprojekt.
Media articles that mention a CVE ID that affects a product developed by Phpprojekt — matched by CVE ID, not by vendor name.