Ravenphpscripts develops lightweight PHP-based web applications and content-management systems such as RavenNuke and Keep It Simple Guest Book, which remain deployed in niche web-hosting and community-site environments. The vendor's vulnerability profile centers durably on application-layer input-handling and code-generation weaknesses, including code injection, cross-site scripting, SQL injection, and exposure of sensitive information, which are characteristic of older PHP frameworks and reflect the security demands of direct user input processing in web applications. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ravenphpscripts over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1635HIGH Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remote attackers to include and execute arbitrary local files vi | Apr 2, 2008 | 7.5 | 34 | NO | YES |
CVE-2009-0677MEDIUM avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remote authenticated users to execute arbitrary code via PHP seq | Feb 22, 2009 | 6.5 | 29 | NO | YES |
CVE-2009-0673MEDIUM Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbi | Feb 22, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-0672MEDIUM SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated administrators to execute arbitrary SQL commands via the use | Feb 22, 2009 | 6.5 | 26 | NO | YES |
CVE-2009-0674MEDIUM images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows remote attackers to determine the existence of local files by | Feb 22, 2009 | 6.0 | 25 | NO | YES |
CVE-2009-0678MEDIUM images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array parameter value that does not correspond to a valid font file, whic | Feb 22, 2009 | 5.0 | 23 | NO | YES |
CVE-2009-0679MEDIUM Cross-site scripting (XSS) vulnerability in the Your Account module in RavenNuke 2.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Feb 22, 2009 | 4.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ravenphpscripts.
Media articles that mention a CVE ID that affects a product developed by Ravenphpscripts — matched by CVE ID, not by vendor name.