Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Simple Php Scripts

First CVE: Oct 31, 2008Active for: 18 yearsTotal CVEs: 16

Simple PHP Scripts develops a narrow line of lightweight web applications, notably a blog and gallery platform, that emphasize ease of deployment for small-scale content sites. The recurring exposure centers on cross-site scripting vulnerabilities arising from improper input neutralization during HTML generation, a pattern characteristic of template-driven PHP applications where user-supplied data flows directly into page output without sufficient sanitization. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 56% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
6.0
Avg CVSS Score
Higher Avg CVSS Score than 2% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Simple Php Scripts over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 31, 2008
17 years ago
Most Recent CVE
Feb 1, 2026
173 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-47918HIGH
Simple CMS 2.1 contains a remote SQL injection vulnerability that allows privileged attackers to inject unfiltered SQL commands in the users module. Attackers can exploit unvalidat
Feb 1, 20268.828NONO
CVE-2021-47919MEDIUM
Simple CMS 2.1 contains a non-persistent cross-site scripting vulnerability in the preview.php file's id parameter. Attackers can inject malicious script code through a GET request
Feb 1, 20266.421NONO
CVE-2021-47917MEDIUM
Simple CMS 2.1 contains a persistent cross-site scripting vulnerability in user input parameters that allows remote attackers to inject malicious script code. Attackers can exploit
Feb 1, 20266.421NONO
CVE-2023-3539MEDIUM
A vulnerability, which was classified as problematic, has been found in SimplePHPscripts Simple Forum PHP 2.7. This issue affects some unknown processing of the file /preview.php o
Jul 7, 20236.121NONO
CVE-2008-4803MEDIUM
Cross-site scripting (XSS) vulnerability in index.php in Simple PHP Scripts gallery 0.1, 0.3, and 0.4 allows remote attackers to inject arbitrary web script or HTML via the gallery
Oct 31, 20084.321NOYES
CVE-2023-3476MEDIUM
A vulnerability was found in SimplePHPscripts GuestBook Script 2.2. It has been classified as problematic. This affects an unknown part of the file preview.php of the component URL
Jun 30, 20236.120NONO
CVE-2023-3475MEDIUM
A vulnerability was found in SimplePHPscripts Event Script 2.1 and classified as problematic. Affected by this issue is some unknown functionality of the file preview.php of the co
Jun 30, 20236.120NONO
CVE-2023-3540MEDIUM
A vulnerability, which was classified as problematic, was found in SimplePHPscripts NewsLetter Script PHP 2.4. Affected is an unknown function of the file /preview.php of the compo
Jul 7, 20236.119NONO
CVE-2023-3538MEDIUM
A vulnerability classified as problematic was found in SimplePHPscripts Photo Gallery PHP 2.0. This vulnerability affects unknown code of the file /preview.php of the component URL
Jul 7, 20235.419NONO
CVE-2023-3537MEDIUM
A vulnerability classified as problematic has been found in SimplePHPscripts News Script PHP Pro 2.4. This affects an unknown part of the file /preview.php of the component URL Par
Jul 7, 20236.119NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
94%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network14 (87.5%)
Unknown2 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High0 (0.0%)
Unknown2 (12.5%)
User Interaction
None3 (18.8%)
Unknown2 (12.5%)
Required11 (68.8%)
Privileges Required
Low4 (25.0%)
High0 (0.0%)
None10 (62.5%)
Unknown2 (12.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
6.2% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Simple Php Scripts.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Simple Php Scripts — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Simple Php Scripts's Products

View all 3 CNAs →

Top CWEs