Postnuke is a content management system with a narrow product footprint that has demonstrated vulnerabilities centered on the web-application input layer. The recurring weakness classes, including SQL injection and forced browsing, reflect common risks in CMS platforms where user-supplied data flows into database queries and access controls. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postnuke over time
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2015HIGH PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter. | Dec 31, 2002 | 7.5 | 40 | NO | YES |
CVE-2006-0147HIGH Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) | Jan 9, 2006 | 7.5 | 36 | NO | YES |
CVE-2008-2012HIGH SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event act | Apr 30, 2008 | 7.5 | 35 | NO | YES |
CVE-2006-0146HIGH The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MA | Jan 9, 2006 | 7.5 | 34 | NO | YES |
CVE-2008-2191MEDIUM SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_ | May 14, 2008 | 6.8 | 32 | NO | YES |
CVE-2006-4968HIGH PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path param | Sep 25, 2006 | 7.5 | 32 | NO | YES |
CVE-2010-1713HIGH SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action. | May 4, 2010 | 7.5 | 30 | NO | YES |
CVE-2006-5733HIGH Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang | Nov 6, 2006 | 7.5 | 29 | NO | YES |
CVE-2001-1460HIGH SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter. | Oct 13, 2001 | 7.5 | 29 | NO | YES |
CVE-2009-0728HIGH SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a sh | Feb 24, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postnuke.
Media articles that mention a CVE ID that affects a product developed by Postnuke — matched by CVE ID, not by vendor name.