Phpwind is a community and forum management platform whose disclosures center on web application vulnerabilities including cross-site scripting, SQL injection, and related input-handling weaknesses inherent to its content management architecture. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpwind over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-7101HIGH SQL injection vulnerability in admin.php in PHPWind 5.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the AdminUser cookie. | Mar 3, 2007 | 7.5 | 28 | NO | YES |
CVE-2019-6691HIGH phpwind 9.0.2.170426 UTF8 allows SQL Injection via the admin.php?m=backup&c=backup&a=doback tabledb[] parameter, related to the "--backup database" option. | Jan 23, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-13472MEDIUM PHPWind 9.1.0 has XSS vulnerabilities in the c and m parameters of the index.php file. | Jul 9, 2019 | 6.1 | 21 | NO | NO |
CVE-2015-4134MEDIUM Open redirect vulnerability in goto.php in phpwind 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter. | May 28, 2015 | 5.8 | 17 | NO | NO |
CVE-2015-4135MEDIUM Cross-site scripting (XSS) vulnerability in goto.php in phpwind 8.7 allows remote attackers to inject arbitrary web script or HTML via the url parameter. | May 28, 2015 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpwind.
Media articles that mention a CVE ID that affects a product developed by Phpwind — matched by CVE ID, not by vendor name.