Phprojekt is a project-management and collaboration platform with a focused footprint centered on a single product. Its vulnerability record spans web-application weaknesses including code injection, cross-site scripting, and sensitive information exposure, reflecting the input-handling and output-encoding demands of web-facing collaboration software. Public exploit code has been associated with this vendor's disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phprojekt over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4204HIGH Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_pre paramete | Aug 17, 2006 | 7.5 | 33 | NO | YES |
CVE-2002-1757HIGH PHProjekt 2.0 through 3.1 relies on the $PHP_SELF variable for authentication, which allows remote attackers to bypass authentication for scripts via a request to a .php file with | Dec 31, 2002 | 7.5 | 29 | NO | YES |
CVE-2004-2739HIGH The setup routine (setup.php) in PHProjekt 4.2.1 and earlier allows remote attackers to modify system configuration via unknown attack vectors. | Dec 31, 2004 | 7.5 | 24 | NO | NO |
CVE-2007-1575HIGH Multiple SQL injection vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to execute arbitrary SQL commands via (1) unspecified | Mar 21, 2007 | 7.5 | 20 | NO | NO |
CVE-2006-5123HIGH Multiple PHP remote file inclusion vulnerabilities in Albrecht Guenther PHProjekt 5.1.x before 5.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lib_p | Oct 3, 2006 | 7.5 | 20 | NO | NO |
CVE-2007-1576MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in PHProjekt 5.2.0, when magic_quotes_gpc is disabled, allow remote authenticated users to inject arbitrary web script or HTML v | Mar 21, 2007 | 4.3 | 19 | NO | NO |
CVE-2002-1759MEDIUM The upload function in PHProjekt 2.0 through 3.1 does not properly verify certain variables related to uploaded data, which allows remote attackers to cause PHProjekt to process ar | Dec 31, 2002 | 5.0 | 19 | NO | NO |
CVE-2002-1760HIGH Multiple SQL injection vulnerabilities in PHProjekt 2.0 through 3.1 allow remote attackers to execute arbitrary SQL commands via the unknown attack vectors. | Dec 31, 2002 | 7.5 | 19 | NO | NO |
CVE-2001-0648MEDIUM Directory traversal vulnerability in PHProjekt 2.1 and earlier allows a remote attacker to conduct unauthorized activities via a dot dot (..) attack on the file module. | Sep 20, 2001 | 5.0 | 19 | NO | NO |
CVE-2004-2740MEDIUM PHP remote file inclusion vulnerability in authform.inc.php in PHProjekt 4.2.3 and earlier allows remote attackers to include arbitrary PHP code via a URL in the path_pre parameter | Dec 31, 2004 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phprojekt.
Media articles that mention a CVE ID that affects a product developed by Phprojekt — matched by CVE ID, not by vendor name.