Social Engine is a focused social networking and community platform whose vulnerability footprint centers on application-level input handling and code execution control, with recurring exposure to code injection, path traversal, and SQL injection weaknesses. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Social Engine over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-41460CRITICAL SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is | Apr 23, 2026 | 9.8 | 32 | NO | NO |
CVE-2009-0400MEDIUM SQL injection vulnerability in blog.php in SocialEngine 3.06 trial allows remote attackers to execute arbitrary SQL commands via the category_id parameter. | Feb 3, 2009 | 6.8 | 30 | NO | YES |
CVE-2026-41461HIGH SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri requ | Apr 23, 2026 | 8.5 | 27 | NO | NO |
CVE-2013-4898MEDIUM Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code | Jan 29, 2014 | 6.5 | 26 | NO | YES |
CVE-2007-6581MEDIUM Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the global_lang paramete | Dec 28, 2007 | 6.4 | 26 | NO | YES |
CVE-2012-6721MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) Forum, (2) Event, and (3) Classifieds plugins in SocialEngine before 4.2.4. | Feb 11, 2020 | 6.3 | 21 | NO | NO |
CVE-2012-6720MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in SocialEngine before 4.2.4 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to music/ | Feb 11, 2020 | 6.1 | 21 | NO | NO |
CVE-2008-3298MEDIUM SocialEngine (SE) before 2.83 grants certain write privileges for templates, which allows remote authenticated administrators to execute arbitrary PHP code. | Jul 25, 2008 | 6.0 | 21 | NO | NO |
CVE-2008-3297HIGH Multiple SQL injection vulnerabilities in SocialEngine (SE) before 2.83 allow remote attackers to execute arbitrary SQL commands via (1) an se_user cookie to include/class_user.php | Jul 25, 2008 | 7.5 | 20 | NO | NO |
CVE-2008-6121HIGH CRLF injection vulnerability in SocialEngine (SE) 2.7 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the PHPSE | Feb 11, 2009 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Social Engine.
Media articles that mention a CVE ID that affects a product developed by Social Engine — matched by CVE ID, not by vendor name.