Php Melody
Vendor:
First CVE: Oct 18, 2017 · Active for 8 years
9
Total CVEs
More Total CVEs than 86% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Php Melody over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 18, 2017
8 years ago
Most Recent CVE
Feb 1, 2026
173 days ago
CVE Severity & Scoring
Php Melody9 CVEs
44%
22%
33%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (88.9%)
Unknown0 (0.0%)
Required1 (11.1%)
Privileges Required
Low5 (55.6%)
High0 (0.0%)
None4 (44.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-5211CRITICAL PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist. | Jan 9, 2018 | 9.8 | 40 | NO | YES |
CVE-2017-15081CRITICAL In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php. | Oct 24, 2017 | 9.8 | 40 | NO | YES |
CVE-2017-15579CRITICAL In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via an aa_pages_per_page cookie in a playlist action to watch.php. | Oct 18, 2017 | 9.8 | 39 | NO | YES |
CVE-2017-15578HIGH In PHPSUGAR PHP Melody before 2.7.3, SQL Injection exists via the image parameter to admin/edit_category.php. | Oct 18, 2017 | 8.8 | 37 | NO | YES |
CVE-2021-47915HIGH PHP Melody version 3.0 contains a remote SQL injection vulnerability in the video edit module that allows authenticated attackers to inject malicious SQL commands. Attackers can ex | Feb 1, 2026 | 8.8 | 28 | NO | NO |
CVE-2021-47912MEDIUM PHP Melody version 3.0 contains multiple non-persistent cross-site scripting vulnerabilities in categories, import, and user import files. Attackers can inject malicious scripts th | Feb 1, 2026 | 6.4 | 22 | NO | NO |
CVE-2021-47914MEDIUM PHP Melody version 3.0 contains a persistent cross-site scripting vulnerability in the edit-video.php submitted parameter that allows remote attackers to inject malicious script co | Feb 1, 2026 | 6.4 | 21 | NO | NO |
CVE-2021-47913MEDIUM PHP Melody 3.0 contains a persistent cross-site scripting vulnerability in the video editor that allows privileged users to inject malicious scripts. Attackers can exploit the WYSI | Feb 1, 2026 | 6.4 | 21 | NO | NO |
CVE-2017-15648MEDIUM In PHPSUGAR PHP Melody before 2.7.3, page_manager.php has XSS via the page_title parameter. | Oct 19, 2017 | 6.1 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (9 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
44.4% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (9 CVEs).
Media Mentions
Signals from CVEs in this product scope (9 CVEs).
Top CNAs Publishing CVEs For Php Melody
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.0 | 4 | 7.0 | 0.3% | 0 | 0 |
| 2.7.1 | 1 | 9.8 | 1.9% | 0 | 1 |
| 2.6.1 | 1 | 9.8 | 2.4% | 0 | 1 |