Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Phpsugar

First CVE: Aug 20, 2009Active for: 17 yearsTotal CVEs: 11
41.4
VTI Score
High

Phpsugar maintains a small set of web-based application and affiliate-management products that skew toward serious outcomes, with a notable share reaching critical severity and a strong tendency toward public exploit availability. The vendor's vulnerability exposure recurs across products such as PHP Melody, PHP-Sugar, and Ultimate RegNow Affiliate through foundational input-handling weakness classes including SQL injection and cross-site scripting, typical of web applications that process user input and generate dynamic content. Current severity, exploit availability, and exposure counts are shown alongside this summary.

FAUCET AI Generated
11
Total CVEs
More Total CVEs than 92% of tracked vendors
0.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Phpsugar over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 9, 2009
17 years ago
Most Recent CVE
Feb 1, 2026
173 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5211CRITICAL
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
Jan 9, 20189.840NOYES
CVE-2017-15081CRITICAL
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.
Oct 24, 20179.840NOYES
CVE-2017-15579CRITICAL
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php.
Oct 18, 20179.839NOYES
CVE-2017-15578HIGH
In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php.
Oct 18, 20178.837NOYES
CVE-2009-2895HIGH
SQL injection vulnerability in rss.php in Ultimate Regnow Affiliate (URA) 3.0 allows remote attackers to execute arbitrary SQL commands via the cat parameter.
Aug 20, 20097.529NOYES
CVE-2021-47915HIGH
PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can ex
Feb 1, 20268.828NONO
CVE-2009-2398MEDIUM
Directory traversal vulnerability in test/index.php in PHP-Sugar 0.80 allows remote attackers to read arbitrary files via a ..// (dot dot slash slash) in the t parameter.
Jul 9, 20095.023NOYES
CVE-2021-47912MEDIUM
PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts th
Feb 1, 20266.422NONO
CVE-2021-47914MEDIUM
PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script co
Feb 1, 20266.421NONO
CVE-2021-47913MEDIUM
PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSI
Feb 1, 20266.421NONO
View all 11 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products11 CVEs
45%
27%
27%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (81.8%)
Unknown2 (18.2%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (81.8%)
High0 (0.0%)
Unknown2 (18.2%)
User Interaction
None8 (72.7%)
Unknown2 (18.2%)
Required1 (9.1%)
Privileges Required
Low5 (45.5%)
High0 (0.0%)
None4 (36.4%)
Unknown2 (18.2%)

Exploit Exposure

Signals from CVEs in this vendor scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
54.5% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Phpsugar.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Phpsugar — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Phpsugar's Products

View all 2 CNAs →

Top CWEs