Postnuke Software Foundation develops a small family of content-management and community-portal applications that, despite modest product breadth, have occupied a prominent niche in self-hosted web services and academic deployments. The vendor's vulnerability profile is anchored in application-layer input-handling weaknesses—SQL injection, cross-site scripting, and path traversal—that recur across its core products including Postnuke, PNphpBB, PostCalendar, and PageSetter, reflecting the parsing and output-encoding demands of templated web applications. These weakness classes have historically attracted public exploit tooling and are characteristic of the era and architecture in which these platforms were built. Defenders running legacy Postnuke installations should treat input-validation and access-control boundaries as persistent risk vectors; live severity, exploitation, and remediation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Postnuke Software Foundation over time
Signals from CVEs in this vendor scope (54 CVEs).
54 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-2015HIGH PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and possibly execute code via the caselist parameter. | Dec 31, 2002 | 7.5 | 40 | NO | YES |
CVE-2006-0147HIGH Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) | Jan 9, 2006 | 7.5 | 36 | NO | YES |
CVE-2008-2012HIGH SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute arbitrary SQL commands via the eid parameter in an event act | Apr 30, 2008 | 7.5 | 35 | NO | YES |
CVE-2006-0146HIGH The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MA | Jan 9, 2006 | 7.5 | 34 | NO | YES |
CVE-2008-2191MEDIUM SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execute arbitrary SQL commands via the id parameter in a display_ | May 14, 2008 | 6.8 | 32 | NO | YES |
CVE-2006-4968HIGH PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path param | Sep 25, 2006 | 7.5 | 32 | NO | YES |
CVE-2010-1713HIGH SQL injection vulnerability in modules.php in PostNuke 0.764 allows remote attackers to execute arbitrary SQL commands via the sid parameter in a News article modload action. | May 4, 2010 | 7.5 | 30 | NO | YES |
CVE-2006-5733HIGH Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang | Nov 6, 2006 | 7.5 | 29 | NO | YES |
CVE-2001-1460HIGH SQL injection vulnerability in article.php in PostNuke 0.62 through 0.64 allows remote attackers to bypass authentication via the user parameter. | Oct 13, 2001 | 7.5 | 29 | NO | YES |
CVE-2009-0728HIGH SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to execute arbitrary SQL commands via the pid parameter in a sh | Feb 24, 2009 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (54 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Postnuke Software Foundation.
Media articles that mention a CVE ID that affects a product developed by Postnuke Software Foundation — matched by CVE ID, not by vendor name.