Pivot's vulnerability profile concentrates in a single product and is characterized by a notably high tendency toward public exploit-code availability, despite a modest volume. The recurring weaknesses center on application-layer input-handling and information-exposure risks, including cross-site scripting, path traversal, and sensitive-data leakage patterns typical of web-facing platforms. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pivot over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-3531HIGH includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload | Jul 12, 2006 | 7.5 | 32 | NO | YES |
CVE-2008-3128MEDIUM Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the t parameter. | Jul 10, 2008 | 5.0 | 26 | NO | YES |
CVE-2006-3533MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML v | Jul 12, 2006 | 5.8 | 26 | NO | YES |
CVE-2006-3532MEDIUM PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via | Jul 12, 2006 | 5.1 | 25 | NO | YES |
CVE-2009-2134MEDIUM pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url parameter, which reveals the installation path in an error messag | Jun 19, 2009 | 5.0 | 23 | NO | YES |
CVE-2009-2133MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrary web script or HTML via the (1) menu or (2) sort parameter | Jun 19, 2009 | 4.3 | 22 | NO | YES |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pivot.
Media articles that mention a CVE ID that affects a product developed by Pivot — matched by CVE ID, not by vendor name.