Pixelpost is a photo-sharing and photoblog application with a narrow product portfolio that occupies a notable niche in the web-publishing landscape. Its vulnerabilities cluster around web-application input-handling and state-management weaknesses—SQL injection, cross-site scripting, cross-site request forgery, and sensitive-information exposure—which are characteristic of server-side PHP-based content-management systems, and these disclosures frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pixelpost over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-1100MEDIUM Multiple SQL injection vulnerabilities in admin/index.php in Pixelpost 1.7.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) findfid, (2) id, (3) sel | Feb 25, 2011 | 6.5 | 33 | NO | YES |
CVE-2009-4899CRITICAL pixelpost 1.7.1 has SQL injection | Oct 28, 2019 | 9.8 | 31 | NO | NO |
CVE-2010-3305HIGH Cross-site request forgery (CSRF) vulnerability in pixelpost 1.7.3 could allow remote attackers to change the admin password. | Nov 12, 2019 | 8.8 | 28 | NO | NO |
CVE-2008-3365MEDIUM Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files | Jul 30, 2008 | 6.8 | 27 | NO | YES |
CVE-2008-0358MEDIUM SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via the parent_id parameter. | Jan 18, 2008 | 6.8 | 27 | NO | YES |
CVE-2018-0604HIGH Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors. | Jun 26, 2018 | 7.2 | 25 | NO | NO |
CVE-2018-0606HIGH SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors. | Jun 26, 2018 | 7.2 | 23 | NO | NO |
CVE-2009-4900MEDIUM pixelpost 1.7.1 has XSS | Oct 28, 2019 | 6.1 | 22 | NO | NO |
CVE-2006-2889MEDIUM Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administra | Jun 7, 2006 | 5.1 | 22 | NO | YES |
CVE-2006-0409MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a c | Jan 25, 2006 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pixelpost.
Media articles that mention a CVE ID that affects a product developed by Pixelpost — matched by CVE ID, not by vendor name.