Phpx is a modestly represented web application framework with a concentrated vulnerability footprint centered on its single namesake product. The durable signal reflects application-layer input-handling weaknesses, particularly SQL injection and related improper neutralization issues, which are characteristic of interpreted web platforms and recur across its disclosure history. Vulnerabilities in this vendor's products frequently acquire public exploit code, making timely patching critical for exposed instances; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Phpx over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0249HIGH PHPX 2.0 through 3.2.4 allows remote attackers to gain access to other accounts by modifying the cookie's PXL variable to reference another userID. | Nov 23, 2004 | 10.0 | 43 | NO | YES |
CVE-2008-3489HIGH SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers to execute arbitrary SQL commands via a PXL cookie. | Aug 6, 2008 | 7.5 | 28 | NO | YES |
CVE-2007-1550HIGH Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (1) image_id or (2) cat_id parameter to (a) gallery.php; the | Mar 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-3968HIGH SQL injection vulnerability in auth.inc.php in PHPX 3.5.9 and earlier allows remote attackers to execute arbitrary SQL commands, bypass authentication, and upload arbitrary PHP cod | Dec 3, 2005 | 7.5 | 28 | NO | YES |
CVE-2008-5000MEDIUM SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via uppercas | Nov 10, 2008 | 6.8 | 26 | NO | YES |
CVE-2004-2364MEDIUM Cross-site request forgery (CSRF) vulnerability in PHPX 3.0 through 3.2.6 allows remote attackers to execute arbitrary commands via URLs that are automatically executed on behalf o | Dec 31, 2004 | 5.0 | 26 | NO | YES |
CVE-2006-0933MEDIUM Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message. | Feb 28, 2006 | 4.3 | 21 | NO | YES |
CVE-2004-2363MEDIUM Validate-Before-Canonicalize vulnerability in the checkURI function in functions.inc.php in PHPX 3.0 through 3.2.6 allows remote attackers to conduct cross-site scripting (XSS) att | Dec 31, 2004 | 4.3 | 21 | NO | YES |
CVE-2007-1549MEDIUM Unrestricted file upload vulnerability in gallery.php in phpx 3.5.15 allows remote attackers to upload and execute arbitrary PHP scripts via an addImage action, which places script | Mar 20, 2007 | 6.8 | 18 | NO | NO |
CVE-2004-0248MEDIUM Cross-site scripting vulnerability (XSS) in PHPX 3.2.3 allows remote attackers to execute arbitrary script as other users by injecting arbitrary HTML or script into (1) keywords ar | Nov 23, 2004 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Phpx.
Media articles that mention a CVE ID that affects a product developed by Phpx — matched by CVE ID, not by vendor name.