Sphider is a modestly represented open-source web search engine and indexing platform whose vulnerability profile skews toward serious outcomes, with a notable share reaching critical severity. The exposure concentrates in the core Sphider product and recurs across application-layer input-handling weaknesses—including cross-site scripting, SQL injection, improper authentication, and general injection flaws—typical of older web applications with limited security hardening. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sphider over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5081CRITICAL sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass | Jan 10, 2020 | 9.8 | 45 | NO | YES |
CVE-2014-5087CRITICAL A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code. | Feb 7, 2020 | 9.8 | 44 | NO | YES |
CVE-2014-5086HIGH A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execut | Feb 10, 2020 | 8.8 | 42 | NO | YES |
CVE-2014-5083HIGH A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary c | Feb 10, 2020 | 8.8 | 37 | NO | YES |
CVE-2014-5192HIGH SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter. | Aug 7, 2014 | 7.5 | 34 | NO | YES |
CVE-2014-5082HIGH Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via t | Aug 6, 2014 | 7.5 | 34 | NO | YES |
CVE-2014-5194MEDIUM Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bo | Aug 7, 2014 | 6.5 | 33 | NO | YES |
CVE-2014-5193MEDIUM Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the category parameter. NOTE: the u | Aug 7, 2014 | 4.3 | 26 | NO | YES |
CVE-2006-1784MEDIUM PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code | Apr 13, 2006 | 5.1 | 25 | NO | YES |
CVE-2007-2411HIGH PHP remote file inclusion vulnerability in index.php in Sphider 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter. NOTE: a third p | May 1, 2007 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sphider.
Media articles that mention a CVE ID that affects a product developed by Sphider — matched by CVE ID, not by vendor name.