Playsms Project maintains a narrowly scoped open-source SMS gateway and messaging platform, with its vulnerability exposure centered on the single Playsms product and the application-layer risks inherent to handling external communications and third-party integrations. The durable signal reflects the product's role as a messaging hub, with observed weakness classes focusing on the inclusion of untrusted functionality—a pattern characteristic of systems that orchestrate communication flows across multiple providers and control spheres. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Playsms Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8644CRITICAL PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. | Feb 5, 2020 | 9.8 | 98 | YES | YES |
CVE-2017-9101CRITICAL import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file. | May 21, 2017 | 9.8 | 86 | NO | YES |
CVE-2017-9080HIGH PlaySMS 1.4 allows remote code execution because PHP code in the name of an uploaded .php file is executed. sendfromfile.php has a combination of Unrestricted File Upload and Code | May 19, 2017 | 8.8 | 79 | NO | YES |
CVE-2009-0103HIGH Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) apps_path[plug] parameter to plugin/ga | Jan 9, 2009 | 7.5 | 32 | NO | YES |
CVE-2008-5881HIGH Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the (1) gatew | Jan 9, 2009 | 7.5 | 31 | NO | YES |
CVE-2022-47034CRITICAL A type juggling vulnerability in the component /auth/fn.php of PlaySMS v1.4.5 and earlier allows attackers to bypass authentication. | Feb 13, 2023 | 9.8 | 29 | NO | NO |
CVE-2024-8880CRITICAL A vulnerability classified as critical has been found in playSMS 1.4.4/1.4.5/1.4.6/1.4.7. Affected is an unknown function of the file /playsms/index.php?app=main&inc=core_auth&rout | Sep 16, 2024 | 9.8 | 28 | NO | NO |
CVE-2004-2263HIGH SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to modify SQL statements via the vc2 cookie. | Dec 31, 2004 | 7.5 | 28 | NO | YES |
CVE-2021-40373CRITICAL playSMS before 1.4.5 allows Arbitrary Code Execution by entering PHP code at the #tabs-information-page of core_main_config, and then executing that code via the index.php?app=main | Sep 10, 2021 | 9.8 | 27 | NO | NO |
CVE-2018-18387HIGH playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse. | Oct 29, 2018 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Playsms Project.
Media articles that mention a CVE ID that affects a product developed by Playsms Project — matched by CVE ID, not by vendor name.