PvpGN is a niche game-server emulation platform whose vulnerability profile, while modest in volume, skews strongly toward critical-severity outcomes. The exposure concentrates in the core PvpGN server and associated statistics components and recurs through SQL injection, link-following, and related input-handling weaknesses that are characteristic of legacy game-server software. Defenders operating or maintaining PvpGN deployments should prioritize patching for critical disclosures; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pvpgn over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-18290CRITICAL An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET sort_direction parameter. | Jun 12, 2018 | 9.8 | 28 | NO | NO |
CVE-2017-18291CRITICAL An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET user parameter. | Jun 12, 2018 | 9.8 | 26 | NO | NO |
CVE-2017-18289CRITICAL An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exist in ladder/stats.php via the GET type parameter. | Jun 12, 2018 | 9.8 | 26 | NO | NO |
CVE-2017-18288CRITICAL An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the GET game parameter. | Jun 12, 2018 | 9.8 | 26 | NO | NO |
CVE-2017-18287CRITICAL An issue was discovered in PvPGN Stats 2.4.6. SQL Injection exists in ladder/stats.php via the POST user_search parameter. | Jun 12, 2018 | 9.8 | 26 | NO | NO |
CVE-2008-5370MEDIUM pvpgn-support-installer in pvpgn 1.8.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pvpgn-support-1.0.tar.gz temporary file. | Dec 8, 2008 | 6.9 | 18 | NO | NO |
CVE-2004-2705MEDIUM Unspecified vulnerability in Player vs. Player Gaming Network (PvPGN) before 1.6.4 allows remote attackers to obtain attributes of arbitrary accounts, including the password hash, | Dec 31, 2004 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pvpgn.
Media articles that mention a CVE ID that affects a product developed by Pvpgn — matched by CVE ID, not by vendor name.