Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pixelpost

First CVE: Jan 25, 2006Active for: 20 yearsTotal CVEs: 17
33.0
VTI Score
Medium

Pixelpost is a photo-sharing and photoblog application with a narrow product portfolio that occupies a notable niche in the web-publishing landscape. Its vulnerabilities cluster around web-application input-handling and state-management weaknesses—SQL injection, cross-site scripting, cross-site request forgery, and sensitive-information exposure—which are characteristic of server-side PHP-based content-management systems, and these disclosures frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
1.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 35% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pixelpost over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 25, 2006
20 years ago
Most Recent CVE
Nov 12, 2019
2,446 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2011-1100MEDIUM
Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) sel
Feb 25, 20116.533NOYES
CVE-2009-4899CRITICAL
pixelpost 1.7.1 has SQL injection
Oct 28, 20199.831NONO
CVE-2010-3305HIGH
Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password.
Nov 12, 20198.828NONO
CVE-2008-3365MEDIUM
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files
Jul 30, 20086.827NOYES
CVE-2008-0358MEDIUM
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter.
Jan 18, 20086.827NOYES
CVE-2018-0604HIGH
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
Jun 26, 20187.225NONO
CVE-2018-0606HIGH
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
Jun 26, 20187.223NONO
CVE-2009-4900MEDIUM
pixelpost 1.7.1 has XSS
Oct 28, 20196.122NONO
CVE-2006-2889MEDIUM
Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administra
Jun 7, 20065.122NOYES
CVE-2006-0409MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a c
Jan 25, 20064.321NOYES
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
65%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network6 (35.3%)
Unknown11 (64.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (35.3%)
High0 (0.0%)
Unknown11 (64.7%)
User Interaction
None3 (17.6%)
Unknown11 (64.7%)
Required3 (17.6%)
Privileges Required
Low0 (0.0%)
High2 (11.8%)
None4 (23.5%)
Unknown11 (64.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
29.4% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelpost.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pixelpost — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pixelpost's Products

View all 3 CNAs →

Top CWEs