Sourceforge hosts a modestly represented portfolio of open-source and community projects spanning utilities, peer-to-peer applications, and web-based tools, with recurring vulnerabilities clustered around input validation, authentication, and path-traversal weaknesses typical of web-facing and user-interactive software. The vendor's disclosures frequently acquire public exploit code, reflecting the accessibility of source-code repositories and the appeal of these applications to security researchers and attackers. Defenders should monitor updates from projects of operational interest on this platform and prioritize patching for internet-exposed instances; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sourceforge over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4837HIGH snmp_api.c in snmpd in Net-SNMP 5.2.x before 5.2.2, 5.1.x before 5.1.3, and 5.0.x before 5.0.10.2, when running in master agentx mode, allows remote attackers to cause a denial of | Dec 31, 2005 | 10.0 | 30 | NO | NO |
CVE-2008-2298HIGH Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin cookie to 1. | May 18, 2008 | 7.5 | 29 | NO | YES |
CVE-2007-1572MEDIUM SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter, a different vector than | Mar 21, 2007 | 6.8 | 26 | NO | YES |
CVE-2008-0501MEDIUM Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page_courante parameter to the t | Jan 30, 2008 | 5.8 | 24 | NO | YES |
CVE-2008-2503HIGH Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors. | May 29, 2008 | 9.3 | 23 | NO | NO |
CVE-2002-2362MEDIUM Cross-site scripting (XSS) vulnerability in form_header.php in MyMarket 1.71 allows remote attackers to inject arbitrary web script or HTML via the noticemsg parameter. | Dec 31, 2002 | 4.3 | 21 | NO | YES |
CVE-2001-0234HIGH NewsDaemon before 0.21b allows remote attackers to execute arbitrary SQL queries and gain privileges via a malformed user_username parameter. | May 3, 2001 | 7.5 | 20 | NO | NO |
CVE-2007-1466MEDIUM Integer overflow in the WP6GeneralTextPacket::_readContents function in WordPerfect Document importer/exporter (libwpd) before 0.8.9 allows user-assisted remote attackers to cause | Mar 16, 2007 | 6.8 | 19 | NO | NO |
CVE-2007-1135MEDIUM Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2 | Mar 2, 2007 | 6.8 | 19 | NO | NO |
CVE-2002-2364MEDIUM Cross-site scripting (XSS) vulnerability in PHP Ticket 0.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a help ticket. | Dec 31, 2002 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sourceforge.
Media articles that mention a CVE ID that affects a product developed by Sourceforge — matched by CVE ID, not by vendor name.