Phpwebsite is a narrowly focused content management system that has accumulated a body of disclosed vulnerabilities concentrated in a single product line. The exposure recurs across parser and input-handling weakness classes including cross-site scripting, SQL injection, and format-string flaws, typical of web application frameworks where user-supplied data flows through templating and database layers. While the vendor's disclosure volume is modest in absolute terms, public exploit code has frequently been made available for its vulnerabilities, creating a durable incentive for defenders to treat patches as high-priority despite the product's narrow deployment scope. Defenders deploying this platform should maintain an aggressive patching cadence and apply input-filtering controls at the application boundary; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpwebsite over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0736MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in phpWebSite 0.9.x and earlier allow remote attackers to execute arbitrary web script via (1) the day parameter in the calendar | Oct 20, 2003 | 6.8 | 33 | NO | YES |
CVE-2002-1135HIGH modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP source code via an inc_prefix parameter that points to the malic | Oct 4, 2002 | 7.5 | 31 | NO | YES |
CVE-2006-5234HIGH Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init | Oct 11, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-1330HIGH Multiple SQL injection vulnerabilities in phpWebsite 0.83 and earlier allow remote attackers to execute arbitrary SQL commands via the sid parameter to (1) friend.php or (2) articl | Mar 21, 2006 | 7.5 | 28 | NO | YES |
CVE-2006-0973HIGH SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic para | Mar 3, 2006 | 7.5 | 28 | NO | YES |
CVE-2005-4792HIGH SQL injection vulnerability in index.php in Appalachian State University phpWebSite 0.10.1 and earlier allows remote attackers to execute arbitrary SQL commands via the module para | Dec 31, 2005 | 7.5 | 28 | NO | YES |
CVE-2003-0735HIGH SQL injection vulnerability in the Calendar module of phpWebSite 0.9.x and earlier allows remote attackers to execute arbitrary SQL queries, as demonstrated using the year paramete | Oct 20, 2003 | 7.5 | 28 | NO | YES |
CVE-2008-0092MEDIUM Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script o | Jan 4, 2008 | 4.3 | 24 | NO | YES |
CVE-2004-1655MEDIUM Cross-site scripting (XSS) vulnerability in phpWebsite 0.9.3-4 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) CM_pid parameter in the commen | Sep 1, 2004 | 4.3 | 21 | NO | YES |
CVE-2003-0738HIGH The calendar module in phpWebSite 0.9.x and earlier allows remote attackers to cause a denial of service (crash) via a long year parameter. | Oct 20, 2003 | 7.8 | 21 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpwebsite.
Media articles that mention a CVE ID that affects a product developed by Phpwebsite — matched by CVE ID, not by vendor name.