Spoonlabs develops the Vivvo Article Management CMS, a content management system where reported vulnerabilities center on path-traversal issues that allow unauthorized access to restricted filesystem resources. This compact vendor profile reflects a narrowly scoped product footprint; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Spoonlabs over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-4715HIGH SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL command | Sep 12, 2006 | 7.5 | 29 | NO | YES |
CVE-2007-0574HIGH SQL injection vulnerability in rss/show_webfeed.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.40 allows remote attackers to execute arbitrary SQL commands via | Jan 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-3939MEDIUM SQL injection vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) CMS 3.4 and earlier allows remote attackers to execute arbitrary SQL commands | Jul 21, 2007 | 6.8 | 27 | NO | YES |
CVE-2007-1031MEDIUM Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote attackers to include and execute arbitrary local files via the | Feb 21, 2007 | 6.8 | 27 | NO | YES |
CVE-2006-4714MEDIUM PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote a | Sep 12, 2006 | 5.1 | 23 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Spoonlabs.
Media articles that mention a CVE ID that affects a product developed by Spoonlabs — matched by CVE ID, not by vendor name.