Phprealty is a real-estate-focused web application with a narrowly scoped product portfolio centered on its single phprealty offering. The recurring vulnerability signal reflects code-injection exposure, a structural weakness in server-side template and query handling that is characteristic of web applications where user-supplied input flows into dynamic code generation. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phprealty over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4834HIGH Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP code via a URL in the MGR parameter to (1) index.php, (2) p_ins | Sep 12, 2007 | 7.5 | 64 | NO | YES |
CVE-2008-4134HIGH PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other versions before 0.05, allows remote attackers to execute arbitr | Sep 19, 2008 | 7.5 | 31 | NO | YES |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phprealty.
Media articles that mention a CVE ID that affects a product developed by Phprealty — matched by CVE ID, not by vendor name.