Status2k is a modestly represented vendor with a narrow product portfolio centered on a single application, yet its vulnerabilities skew strongly toward critical-severity outcomes and frequently acquire public exploit code. The recurring weakness classes—including improper input validation, sensitive-information exposure, code injection, cross-site scripting, and SQL injection—reflect the application-layer and data-handling risks endemic to web-facing software. Defenders should prioritize patching this vendor's disclosures despite its limited scope, given the severity tendency and exploit availability; live exploitation activity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Status2k over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-5091CRITICAL A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code. | Feb 7, 2020 | 9.8 | 49 | NO | YES |
CVE-2014-5093CRITICAL Status2k does not remove the install directory allowing credential reset. | Jan 10, 2020 | 9.8 | 43 | NO | YES |
CVE-2014-5092HIGH Status2k allows Remote Command Execution in admin/options/editpl.php. | Jan 10, 2020 | 8.8 | 39 | NO | YES |
CVE-2014-5089HIGH SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter. | Aug 6, 2014 | 7.5 | 33 | NO | YES |
CVE-2014-5090MEDIUM admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin | Aug 6, 2014 | 6.5 | 31 | NO | YES |
CVE-2014-5094MEDIUM Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function. | Oct 20, 2014 | 5.0 | 28 | NO | YES |
CVE-2014-5088MEDIUM Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php. | Aug 6, 2014 | 4.3 | 25 | NO | YES |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Status2k.
Media articles that mention a CVE ID that affects a product developed by Status2k — matched by CVE ID, not by vendor name.