Sphpblog is a niche blogging platform whose vulnerability exposure centers on its core product and recurs through cross-site request forgery flaws and general input-handling weaknesses. Current vulnerability counts, severity breakdown, and exploitation status are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sphpblog over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-6033HIGH Multiple directory traversal vulnerabilities in Simple PHP Blog (SPHPBlog), probably 0.4.8, allow remote attackers to read arbitrary files and possibly include arbitrary PHP code v | Nov 21, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-6032MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Simple PHP Blog (SPHPBlog), probably 0.4.8, allow remote attackers to inject arbitrary web script or HTML via (1) the action | Nov 21, 2006 | 6.8 | 18 | NO | NO |
CVE-2005-1136MEDIUM Simple PHP Blog (sphpBlog) 0.4.0 stores the (1) password.txt and (2) config.txt files under the web document root, which allows remote attackers to obtain sensitive information and | Apr 14, 2005 | 5.0 | 15 | NO | NO |
CVE-2007-5572MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in Simple PHP Blog (SPHPBlog) 0.4.9 allow remote attackers to perform delete actions as administrators via (1) the block_ | Oct 18, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sphpblog.
Media articles that mention a CVE ID that affects a product developed by Sphpblog — matched by CVE ID, not by vendor name.