Phpvibe operates a social-networking and media-sharing platform whose vulnerability profile centers on web-application input handling and file-management weaknesses, including cross-site scripting, path-traversal, and unrestricted file-upload flaws. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpvibe over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-39171CRITICAL Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and c | Jul 9, 2024 | 9.8 | 29 | NO | NO |
CVE-2024-6083CRITICAL A vulnerability, which was classified as critical, was found in PHPVibe 11.0.46. Affected is an unknown function of the file /app/uploading/upload-mp3.php of the component Media Up | Jun 18, 2024 | 9.8 | 25 | NO | NO |
CVE-2015-5399MEDIUM Cross-site scripting (XSS) vulnerability in PHPVibe before 4.21 allows remote authenticated users to inject arbitrary web script or HTML via a comment. | Aug 26, 2016 | 5.4 | 23 | NO | YES |
CVE-2024-6082MEDIUM A vulnerability, which was classified as problematic, has been found in PHPVibe 11.0.46. This issue affects some unknown processing of the file functionalities.global.php of the co | Jun 17, 2024 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpvibe.
Media articles that mention a CVE ID that affects a product developed by Phpvibe — matched by CVE ID, not by vendor name.