Phpwhois Project maintains a PHP-based domain-lookup library with a narrow scope that has a moderate presence in web applications requiring WHOIS query functionality. The durable signal centers on input-handling and code-generation issues, with recurring vulnerability classes including cross-site scripting and code injection, reflecting the parsing demands of untrusted WHOIS protocol responses. Current exposure counts and live security metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpwhois Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-5243CRITICAL phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. | Aug 20, 2018 | 9.8 | 32 | NO | NO |
CVE-2021-43698MEDIUM phpWhois (last update Jun 30 2021) is affected by a Cross Site Scripting (XSS) vulnerability. In file example.php, the exit function will terminate the script and print the message | Nov 29, 2021 | 6.1 | 21 | NO | NO |
CVE-2015-3998MEDIUM Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary we | May 17, 2017 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpwhois Project.
Media articles that mention a CVE ID that affects a product developed by Phpwhois Project — matched by CVE ID, not by vendor name.