Planetluc develops a narrowly scoped line of web-based personal publishing and content-management applications such as MyNews, RateMe, MyGallery, and SignMe, where vulnerabilities cluster around client-side input handling and request-forgery defenses. The vendor's disclosures have a recurring tendency toward public exploit availability and recur through weakness classes including cross-site scripting, cross-site request forgery, and related web-layer input-handling flaws that are characteristic of application-facing exposure. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Planetluc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0723MEDIUM Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows remote attackers to inject arbitrary web script or HTML via the | Feb 12, 2008 | 4.3 | 21 | NO | YES |
CVE-2006-2208MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page pa | May 5, 2006 | 4.3 | 21 | NO | YES |
CVE-2008-4899MEDIUM Cross-site request forgery (CSRF) vulnerability in Planetluc RateMe 1.3.3 allows remote attackers to perform unauthorized actions as other users via unspecified vectors. | Nov 4, 2008 | 6.8 | 18 | NO | NO |
CVE-2008-4898MEDIUM Cross-site scripting (XSS) vulnerability in planetluc RateMe 1.3.3 allows remote attackers to inject arbitrary web script or HTML via the rate parameter in a submit rate action. | Nov 4, 2008 | 4.3 | 14 | NO | NO |
CVE-2008-4892MEDIUM Cross-site scripting (XSS) vulnerability in gallery.inc.php in Planetluc MyGallery 1.7.2 and earlier, and possibly other versions before 1.8.1, allows remote attackers to inject ar | Nov 4, 2008 | 4.3 | 14 | NO | NO |
CVE-2008-4891MEDIUM Cross-site scripting (XSS) vulnerability in signme.inc.php in Planetluc SignMe 1.5 before 1.55 allows remote attackers to inject arbitrary web script or HTML via the hash parameter | Nov 4, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Planetluc.
Media articles that mention a CVE ID that affects a product developed by Planetluc — matched by CVE ID, not by vendor name.